Vulnerability PYSEC-2026-928
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 months ago
July 06, 2026 at 08:03 AM UTC
OpenStack Swift Cross-site Scriping vulnerability
Summary
OpenStack Swift Cross-site Scriping vulnerability
Details
Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.
References
- ADVISORY — nvd.nist.gov
- WEB — access.redhat.com
- WEB — access.redhat.com
- WEB — bugzilla.redhat.com
- PACKAGE — opendev.org
- WEB — review.openstack.org
- WEB — review.openstack.org
- WEB — web.archive.org
- WEB — lists.openstack.org
- WEB — www.openwall.com
- WEB — www.ubuntu.com
- PACKAGE — pypi.org
- ADVISORY — github.com
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
2 months ago
OpenStack Swift: s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body
2.36.0 - 2.36.1 and 2.37.0 - 2.37.1 PYSEC-2026-3080
2.36.0 - 2.36.1 and 2.37.0 - 2.37.1 PYSEC-2026-3080
Medium Risk
2 months ago
OpenStack Swift XML external entities (XXE) Injection
1.0.2 - 2.28.0 and 2.29.0 - 2.29.1 and 2.30.0 PYSEC-2026-927
1.0.2 - 2.28.0 and 2.29.0 - 2.29.1 and 2.30.0 PYSEC-2026-927
Unknown
2 months ago
OpenStack Swift allows authenticated users to cause a denial of service
1.0.2 PYSEC-2026-935
1.0.2 PYSEC-2026-935
High Risk
2 months ago
OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
1.0.2 PYSEC-2026-929
1.0.2 PYSEC-2026-929
High Risk
2 months ago
OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
1.0.2 PYSEC-2026-932
1.0.2 PYSEC-2026-932
Impacted packages
Timeline
Published
2 months ago
July 06, 2026 at 08:03 AM UTC
Last Modified
2 months ago
July 07, 2026 at 11:45 AM UTC