In Ceph before 12.2.3 and 13.x through 13.0.1, the rgwcivetweb.cc RGWCivetWeb::initenv function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-7262.json"