Vulnerability PYSEC-2026-927
Medium Risk
MEDIUM RISK
CVSS Score: 6.5
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 months ago
July 07, 2026 at 10:17 AM UTC
OpenStack Swift XML external entities (XXE) Injection
1.0.2 - 2.28.0 and 2.29.0 - 2.29.1 and 2.30.0
1.0.2 - 2.28.0 and 2.29.0 - 2.29.1 and 2.30.0
Summary
OpenStack Swift XML external entities (XXE) Injection
Details
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).
References
- ADVISORY — nvd.nist.gov
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- PACKAGE — github.com
- WEB — launchpad.net
- WEB — lists.debian.org
- WEB — security.openstack.org
- WEB — www.debian.org
- PACKAGE — pypi.org
- ADVISORY — github.com
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
2 months ago
OpenStack Swift: s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body
2.36.0 - 2.36.1 and 2.37.0 - 2.37.1 PYSEC-2026-3080
2.36.0 - 2.36.1 and 2.37.0 - 2.37.1 PYSEC-2026-3080
Unknown
2 months ago
OpenStack Swift allows authenticated users to cause a denial of service
1.0.2 PYSEC-2026-935
1.0.2 PYSEC-2026-935
Unknown
2 months ago
OpenStack Swift Cross-site Scriping vulnerability
PYSEC-2026-928
High Risk
2 months ago
OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
1.0.2 PYSEC-2026-929
1.0.2 PYSEC-2026-929
High Risk
2 months ago
OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
1.0.2 PYSEC-2026-932
1.0.2 PYSEC-2026-932
Impacted packages
Timeline
Published
2 months ago
July 07, 2026 at 10:17 AM UTC
Fixed (2.30.1)
3 years ago
January 31, 2023 at 03:19 PM UTC
Fixed (2.29.2)
3 years ago
January 31, 2023 at 03:24 PM UTC
Fixed (2.28.1)
3 years ago
February 02, 2023 at 11:28 AM UTC
Last Modified
2 months ago
July 07, 2026 at 11:45 AM UTC