WSGI Transport Vulnerability in OpenStack Zaqar Affects Multiple Deployments
CVE-2026-97404

9.2CRITICAL

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-97404?

In OpenStack Zaqar prior to version 22.0.2, the WSGI transport improperly handles the URL-Signature header. An unauthenticated remote attacker who knows the UUID of a target project can exploit this by sending requests with an empty URL-Signature header. This allows the attacker to bypass Keystone authentication and pre-signed URL verification mechanisms. Consequently, this vulnerability enables the attacker to read, enumerate, create, and delete a project's queues, messages, claims, and subscriptions. Additionally, if the attacker successfully claims an administrative role, they can execute administrative operations, such as managing pools and flavors, in deployments utilizing admin_mode. It is important to note that this issue affects only deployments that use the WSGI transport with a configured authentication strategy; deployments relying on the websocket transport remain unaffected.

Affected Version(s)

Zaqar 1.0.0 < 20.1.2

Zaqar 21.0.0 < 21.0.2

Zaqar 22.0.0 < 22.0.2

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.