oss-sec mailing list archives
[OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-pending)
From: Goutham Pacha Ravi <gouthampravi () gmail com>
Date: Tue, 28 Jul 2026 08:28:03 -0700
============================================================== OSSA-2026-031: Swift proxy denial of service via Accept header ============================================================== :Date: July 28, 2026 :CVE: CVE-2026-pending Affects ~~~~~~~ - Swift: >=1.9.1 <2.35.4, >=2.36.0 <2.36.3, >=2.37.0 <2.37.3, ==2.38.0 Description ~~~~~~~~~~~Christian Schwede from NVIDIA reported a denial of service vulnerability in Swift's proxy server. The Accept header parser is vulnerable to catastrophic regular expression backtracking. An unauthenticated attacker can send crafted requests that exhaust proxy worker threads, rendering the service unavailable. All deployments running Swift proxy with versions between 1.9.1 and the fixed releases listed below are affected.
Patches ~~~~~~~ - https://review.opendev.org/998953 (2025.1/epoxy) - https://review.opendev.org/998952 (2025.2/flamingo) - https://review.opendev.org/998951 (2026.1/gazpacho) - https://review.opendev.org/998950 (2026.2/hibiscus (development)) Credits ~~~~~~~ - Christian Schwede from NVIDIA References ~~~~~~~~~~ - https://launchpad.net/bugs/2158771 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending -- Goutham Pacha Ravi OpenStack Vulnerability Management Team https://security.openstack.org/vmt.html
Attachment:
OpenPGP_0x0638DAD3B82C3988.asc
Description: OpenPGP public key
Attachment:
OpenPGP_signature.asc
Description: OpenPGP digital signature
Current thread:
- [OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-pending) Goutham Pacha Ravi (Jul 28)
- Re: [OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-71190) Goutham Pacha Ravi (Aug 05)
