Vulnerability PYSEC-2026-3080

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 months ago
July 13, 2026 at 03:19 PM UTC
OpenStack Swift: s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body
2.36.0 - 2.36.1 and 2.37.0 - 2.37.1
2.36.0 - 2.36.1 and 2.37.0 - 2.37.1

Summary

OpenStack Swift: s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body

Details

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0.

Impacted packages

Timeline

Published
2 months ago
July 13, 2026 at 03:19 PM UTC
Last Modified
2 months ago
July 13, 2026 at 04:33 PM UTC