Search CVE reports


Toggle filters

151 – 160 of 42041 results

Status is adjusted based on your filters.


CVE-2026-71201

Medium priority
Needs evaluation

In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.

1 affected package

ironic

Package 24.04 LTS
ironic Needs evaluation
Show less packages

CVE-2026-67592

Medium priority
Needs evaluation

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid...

1 affected package

qpid-proton

Package 24.04 LTS
qpid-proton Needs evaluation
Show less packages

CVE-2026-67591

Medium priority
Needs evaluation

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0,...

1 affected package

qpid-proton

Package 24.04 LTS
qpid-proton Needs evaluation
Show less packages

CVE-2026-67590

Medium priority
Needs evaluation

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version...

1 affected package

qpid-proton

Package 24.04 LTS
qpid-proton Needs evaluation
Show less packages

CVE-2026-71192

Medium priority
Needs evaluation

In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An attacker can inject these headers into a signed...

1 affected package

swift

Package 24.04 LTS
swift Needs evaluation
Show less packages

CVE-2026-71191

Medium priority
Needs evaluation

In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned...

1 affected package

swift

Package 24.04 LTS
swift Needs evaluation
Show less packages

CVE-2026-71190

Medium priority
Needs evaluation

In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The "qdtext" pattern (?:[^"]|\\.)* allows an unauthenticated remote attacker...

1 affected package

swift

Package 24.04 LTS
swift Needs evaluation
Show less packages

CVE-2026-67589

Medium priority
Needs evaluation

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade...

1 affected package

qpid-proton

Package 24.04 LTS
qpid-proton Needs evaluation
Show less packages

CVE-2026-67588

Medium priority
Needs evaluation

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to...

1 affected package

qpid-proton

Package 24.04 LTS
qpid-proton Needs evaluation
Show less packages

CVE-2026-55707

Medium priority
Needs evaluation

In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating...

1 affected package

neutron

Package 24.04 LTS
neutron Needs evaluation
Show less packages