[Git][security-tracker-team/security-tracker][master] CVEs for swift issues now assigned

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 5 09:37:22 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
89258b23 by Salvatore Bonaccorso at 2026-08-05T10:36:28+02:00
CVEs for swift issues now assigned

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -9,12 +9,6 @@ CVE-2026-7753 (The Cost Calculator Builder plugin for WordPress is vulnerable to
 CVE-2026-71201 (In OpenStack Ironic through 38.0.0, a project reader that makes a craf ...)
 	- ironic <unfixed>
 	NOTE: https://bugs.launchpad.net/ironic/+bug/2162715
-CVE-2026-71192 (In OpenStack Swift through 2.38.0, the S3API middleware does not sanit ...)
-	TODO: check
-CVE-2026-71191 (In OpenStack Swift through 2.38.0, S3API middleware does not enforce t ...)
-	TODO: check
-CVE-2026-71190 (In OpenStack Swift through 2.38.0, the proxy server Accept header pars ...)
-	TODO: check
 CVE-2026-70620 (Odysseus before commit 87babb5 contains a server-side request forgery  ...)
 	NOT-FOR-US: Odysseus
 CVE-2026-70619 (Odysseus before commit bf325f6 contains a missing authorization vulner ...)
@@ -3094,11 +3088,15 @@ CVE-2026-7260 (Circular symbolic links in phar archives could lead to unbounded
 	- php7.4 <removed>
 	NOTE: https://github.com/php/php-src/security/advisories/GHSA-vc5h-9ppw-p5f3
 	NOTE: Fixed by: https://github.com/php/php-src/commit/16af1694dd4e0d0e4a24f90740651d3053edffa3 (php-8.4.24)
-CVE-2026-XXXX [OSSA-2026-031 Swift: Proxy denial of service via Accept header]
+CVE-2026-71190 [OSSA-2026-031 Swift: Proxy denial of service via Accept header]
 	- swift 2.37.1-6 (bug #1142973)
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-031.html
 	NOTE: https://bugs.launchpad.net/swift/+bug/2158771
-CVE-2026-XXXX [OSSA-2026-030 Swift: S3API header authorization bypass]
+CVE-2026-71192 [OSSA-2026-030 Swift: S3API header authorization bypass]
+	- swift 2.37.1-6 (bug #1142972)
+	NOTE: https://security.openstack.org/ossa/OSSA-2026-030.html
+	NOTE: https://bugs.launchpad.net/swift/+bug/2158733
+CVE-2026-71191 [OSSA-2026-030 Swift: S3API header authorization bypass]
 	- swift 2.37.1-6 (bug #1142972)
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-030.html
 	NOTE: https://bugs.launchpad.net/swift/+bug/2158733



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/89258b236677d891a50ee3a3f62178698cda447b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/89258b236677d891a50ee3a3f62178698cda447b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/8ad1d932/attachment.htm>


More information about the debian-security-tracker-commits mailing list