In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.
{
"cna_assigner": "mitre",
"cwe_ids": [
"CWE-863"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71191.json"
}{
"extracted_events": [
{
"introduced": "2.18.0"
},
{
"fixed": "2.35.4"
},
{
"introduced": "2.36.0"
},
{
"fixed": "2.36.3"
},
{
"introduced": "2.37.0"
},
{
"fixed": "2.37.3"
},
{
"introduced": "2.38.0"
},
{
"last_affected": "2.38.0"
}
],
"source": "AFFECTED_FIELD"
}