Search CVE reports


Toggle filters

1 – 10 of 65 results


CVE-2026-43000

Medium priority
Needs evaluation

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted...

1 affected package

keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-42999

Medium priority
Needs evaluation

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary...

1 affected package

keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-42998

Medium priority
Needs evaluation

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the...

1 affected package

keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-43001

Medium priority
Needs evaluation

An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential....

1 affected package

keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-40683

Medium priority
Needs evaluation

In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the...

1 affected package

keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-33551

Medium priority
Needs evaluation

An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2...

1 affected package

keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-22797

Medium priority
Fixed

An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize...

1 affected package

python-keystonemiddleware

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-keystonemiddleware Fixed Not affected Not affected Not affected
Show less packages

CVE-2025-65073

Medium priority

Some fixes available 9 of 24

OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.

3 affected packages

keystone, swift, heat

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Fixed Fixed Fixed Ignored Ignored
swift Vulnerable Fixed Fixed Needs evaluation Needs evaluation
heat Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-2447

Low priority

Some fixes available 1 of 8

A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to...

1 affected package

keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Not affected Not affected Fixed Vulnerable Vulnerable
Show less packages

CVE-2021-3563

Low priority

Some fixes available 1 of 11

A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this...

1 affected package

keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Not affected Not affected Fixed Vulnerable Vulnerable
Show less packages