Vulnerability PYSEC-2026-932
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 months ago
July 06, 2026 at 08:03 AM UTC
OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
1.0.2
1.0.2
Summary
OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
Details
OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.
References
- ADVISORY — nvd.nist.gov
- WEB — web.archive.org
- WEB — security.openstack.org
- WEB — rhn.redhat.com
- WEB — rhn.redhat.com
- WEB — rhn.redhat.com
- WEB — lists.fedoraproject.org
- WEB — github.com
- PACKAGE — github.com
- WEB — bugzilla.redhat.com
- WEB — bugs.launchpad.net
- WEB — access.redhat.com
- WEB — access.redhat.com
- WEB — access.redhat.com
- WEB — access.redhat.com
- WEB — access.redhat.com
- WEB — access.redhat.com
- WEB — access.redhat.com
- PACKAGE — pypi.org
- ADVISORY — github.com
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
2 months ago
OpenStack Swift: s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body
2.36.0 - 2.36.1 and 2.37.0 - 2.37.1 PYSEC-2026-3080
2.36.0 - 2.36.1 and 2.37.0 - 2.37.1 PYSEC-2026-3080
Medium Risk
2 months ago
OpenStack Swift XML external entities (XXE) Injection
1.0.2 - 2.28.0 and 2.29.0 - 2.29.1 and 2.30.0 PYSEC-2026-927
1.0.2 - 2.28.0 and 2.29.0 - 2.29.1 and 2.30.0 PYSEC-2026-927
Unknown
2 months ago
OpenStack Swift allows authenticated users to cause a denial of service
1.0.2 PYSEC-2026-935
1.0.2 PYSEC-2026-935
Unknown
2 months ago
OpenStack Swift Cross-site Scriping vulnerability
PYSEC-2026-928
High Risk
2 months ago
OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
1.0.2 PYSEC-2026-929
1.0.2 PYSEC-2026-929
Impacted packages
Timeline
Published
2 months ago
July 06, 2026 at 08:03 AM UTC
Last Modified
2 months ago
July 07, 2026 at 11:45 AM UTC