[Git][security-tracker-team/security-tracker][master] CVEs for swift issues now assigned
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 5 09:37:22 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
89258b23 by Salvatore Bonaccorso at 2026-08-05T10:36:28+02:00
CVEs for swift issues now assigned
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -9,12 +9,6 @@ CVE-2026-7753 (The Cost Calculator Builder plugin for WordPress is vulnerable to
CVE-2026-71201 (In OpenStack Ironic through 38.0.0, a project reader that makes a craf ...)
- ironic <unfixed>
NOTE: https://bugs.launchpad.net/ironic/+bug/2162715
-CVE-2026-71192 (In OpenStack Swift through 2.38.0, the S3API middleware does not sanit ...)
- TODO: check
-CVE-2026-71191 (In OpenStack Swift through 2.38.0, S3API middleware does not enforce t ...)
- TODO: check
-CVE-2026-71190 (In OpenStack Swift through 2.38.0, the proxy server Accept header pars ...)
- TODO: check
CVE-2026-70620 (Odysseus before commit 87babb5 contains a server-side request forgery ...)
NOT-FOR-US: Odysseus
CVE-2026-70619 (Odysseus before commit bf325f6 contains a missing authorization vulner ...)
@@ -3094,11 +3088,15 @@ CVE-2026-7260 (Circular symbolic links in phar archives could lead to unbounded
- php7.4 <removed>
NOTE: https://github.com/php/php-src/security/advisories/GHSA-vc5h-9ppw-p5f3
NOTE: Fixed by: https://github.com/php/php-src/commit/16af1694dd4e0d0e4a24f90740651d3053edffa3 (php-8.4.24)
-CVE-2026-XXXX [OSSA-2026-031 Swift: Proxy denial of service via Accept header]
+CVE-2026-71190 [OSSA-2026-031 Swift: Proxy denial of service via Accept header]
- swift 2.37.1-6 (bug #1142973)
NOTE: https://security.openstack.org/ossa/OSSA-2026-031.html
NOTE: https://bugs.launchpad.net/swift/+bug/2158771
-CVE-2026-XXXX [OSSA-2026-030 Swift: S3API header authorization bypass]
+CVE-2026-71192 [OSSA-2026-030 Swift: S3API header authorization bypass]
+ - swift 2.37.1-6 (bug #1142972)
+ NOTE: https://security.openstack.org/ossa/OSSA-2026-030.html
+ NOTE: https://bugs.launchpad.net/swift/+bug/2158733
+CVE-2026-71191 [OSSA-2026-030 Swift: S3API header authorization bypass]
- swift 2.37.1-6 (bug #1142972)
NOTE: https://security.openstack.org/ossa/OSSA-2026-030.html
NOTE: https://bugs.launchpad.net/swift/+bug/2158733
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/89258b236677d891a50ee3a3f62178698cda447b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/89258b236677d891a50ee3a3f62178698cda447b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/8ad1d932/attachment.htm>
More information about the debian-security-tracker-commits
mailing list