Where
-Infinity
0

oss-sec[OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone authentication (CVE-2026-66139)

Openstack Zaqar[OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone authentication (CVE-2026-66139)

Risk 34
Severity
4.8
First published (updated )

Openstack Ironic Python Agent[OSSA-2026-027] OpenStack Ironic Python Agent: Command execution via unsanitized config (CVE-2026-66138)

Risk 70
Severity
7.2
First published (updated )

oss-sec[OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone authentication (CVE-2026-pending)

Openstack Ironic Python Agent[OSSA-2026-028] OpenStack Ironic Python Agent: Cdential extraction via malicious container (CVE-2026-54422)

Risk 33
Severity
5.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

oss-sec[OSSA-2026-027] OpenStack Ironic Python Agent: Command execution via unsanitized config (CVE-2026-pending)

Openstack GlanceGlance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass

Risk 43
Severity
8.2
First published (updated )

Openstack IronicOpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project withou…

Risk 41
Severity
5.5
First published (updated )

oss-sec[OSSA-2026-026] Ironic: Insufficient Access Controls garding pant/child nodes

First published (updated )

Openstack Ironic[OSSA-2026-025] Ironic: RBAC Bypass in IPMI Raw Command Execution (CVE-2026-54423)

Risk 61
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

oss-sec[OSSA-2026-025] Ironic: RBAC Bypass in IPMI Raw Command Execution (CVE-2026-54423)

First published (updated )

Openstack Swift[OSSA-2026-024] OpenStack Swift: Swift proxy-server SSRF via header injection (CVE-2026-50221)

Risk 36
Severity
5.3
First published (updated )

oss-sec[OSSA-2026-024] OpenStack Swift: Swift proxy-server SSRF via header injection (CVE-2026-50221)

Openstack OpenStack HorizonOS Command Injection

Risk 49
Severity
6
First published (updated )

oss-sec[OSSA-2026-023] Ironic: Sensitive properties turned undacted in POST and PATCH HTTP sponses (CVE-2026-54421)

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

oss-sec[OSSA-2026-022] OpenStack Nova: Nova scheduler hint injection bypasses Placement source claims and scheduling constraints (CVE-2026-46448)

Openstack Nova[OSSA-2026-022] OpenStack Nova: Nova scheduler hint injection bypasses Placement source claims and scheduling constraints (CVE-2026-46448)

Risk 59
Severity
8.5
First published (updated )

oss-sec[OSSA-2026-017] Errata 1: Ironic: Script injection during node boot via linux command line override (CVE-2026-46447)

Openstack Ironic[OSSA-2026-023] Ironic: Sensitive properties turned undacted in POST and PATCH HTTP sponses (CVE-2026-54421)

Risk 39
Severity
6.8
First published (updated )

Openstack IronicIn OpenStack Ironic 32 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Openstack OpenStack Ironic[OSSN-0099] Denial of Service in OpenStack Ironic under duced process stack size (CVE-2026-50589)

Risk 46
Severity
7.5
First published (updated )

oss-sec[OSSA-2026-021] OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shad networks (CVE-2026-pending)

Openstack NeutronIn OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared networ…

Risk 14
Severity
2.2
First published (updated )

Openstack oslo.messagingAn issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitM…

Risk 33
Severity
7
First published (updated )

oss-sec[OSSA-2026-021] OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shad networks (CVE-2026-pending)

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Openstack MistralOpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. The…

Risk 33
Severity
7
First published (updated )

Openstack oslo.messagingAn issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitM…

Risk 56
Severity
7.4
First published (updated )

Openstack Mistral[OSSA-2026-020] OpenStack Mistral: Mistral policy enforcement bypass allows unauthorized public source cation and arbitrary code execution (CVE-2026-41283)

Risk 88
Severity
9.9
First published (updated )

Openstack Ironic[OSSA-2026-019] Ironic: File Extraction from conductor via pxe_template (CVE-2026-44917)

Risk 31
Severity
4.9
First published (updated )

Openstack Ironic[OSSA-2026-018] Ironic: File overwrite on Ironic conductor via path traversal in ISO handling (CVE-2026-48681)

Risk 63
Severity
8.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203