CVE-2026-50221

Source
https://cve.org/CVERecord?id=CVE-2026-50221
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50221.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-50221
Downstream
Published
2026-06-23T17:03:32.971Z
Modified
2026-08-12T03:51:33.036524715Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:N CVSS Calculator
Summary
[none]
Details

In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update requests to an attacker-controlled server, enabling server-side request forgery. The SSRF requests expose internal cluster metadata including storage policy indexes, partition mappings, device names, and when at rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key. The attacker can also cause "ghost listings" in arbitrary containers via the shard-range redirect mechanism.

Database specific
{
    "cwe_ids": [
        "CWE-918"
    ],
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50221.json"
}
References

Affected packages

Git / github.com/openstack/swift

Affected ranges

Type
GIT
Repo
https://github.com/openstack/swift
Events
Database specific
Show details
{
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "2.35.3"
        },
        {
            "introduced": "2.36.0"
        },
        {
            "fixed": "2.36.2"
        },
        {
            "introduced": "2.37.0"
        },
        {
            "fixed": "2.37.2"
        }
    ]
}
Type
GIT
Repo
https://opendev.org/openstack/swift
Events
Introduced
bfa9139649c0ac7f75e8c9503cb04d06f7bae0b9
Fixed
980b5b6987fa8d4ea5cdfa8256b00430d8bfc2d1
Introduced
82cb5a5d78b91c6af258cd8f06d30f69be90fa18
Fixed
bbd9c5e012d9f4821d67b9dfd538180de63e733b
Introduced
555026d200337b39c97eb9dafd26901ff40c7a1d
Fixed
f701907958c791f10ebb775690b9d21d39d92ae8
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "2.35.3"
        },
        {
            "introduced": "2.36.0"
        },
        {
            "fixed": "2.36.2"
        },
        {
            "introduced": "2.37.0"
        },
        {
            "fixed": "2.37.2"
        }
    ]
}

Affected versions

2.*
2.36.0
2.36.1
2.37.0
2.37.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50221.json"