CVE-2026-71191

Source
https://cve.org/CVERecord?id=CVE-2026-71191
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71191.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-71191
Downstream
Published
2026-08-05T05:01:20.971Z
Modified
2026-08-25T04:03:33.337934877Z
Severity
  • 6.0 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
[none]
Details

In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target projectid, container name, and object name are known. This affects all deployments using the default s3acl=false configuration.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71191.json",
    "cwe_ids": [
        "CWE-863"
    ]
}
References

Affected packages

Git / opendev.org/openstack/swift

Affected ranges

Type
GIT
Repo
https://opendev.org/openstack/swift
Events
Introduced
f270466de363499894317b7c671f65e8a912bd53
Fixed
fc875f93e82edf98805d0eead3e3c961673c3ef8
Introduced
82cb5a5d78b91c6af258cd8f06d30f69be90fa18
Fixed
deaa3e4691bb19224f5ef57e7fbcd08b7eff5277
Introduced
555026d200337b39c97eb9dafd26901ff40c7a1d
Fixed
5104042f12efcaf90c28b656a378da8959004826
Introduced
9f5881d5143fd06a328bde2713cd9c61df579289
Last affected
9f5881d5143fd06a328bde2713cd9c61df579289
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "2.18.0"
        },
        {
            "fixed": "2.35.4"
        },
        {
            "introduced": "2.36.0"
        },
        {
            "fixed": "2.36.3"
        },
        {
            "introduced": "2.37.0"
        },
        {
            "fixed": "2.37.3"
        },
        {
            "introduced": "2.38.0"
        },
        {
            "last_affected": "2.38.0"
        }
    ]
}

Affected versions

2.*
2.18.0
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.25.0
2.26.0
2.27.0
2.28.0
2.29.0
2.29.1
2.30.0
2.31.0
2.31.1
2.32.0
2.33.0
2.34.0
2.35.0
2.35.1
2.35.2
2.35.3
2.36.0
2.36.1
2.36.2
2.37.0
2.37.1
2.37.2
2.38.0
Other
victoria-em
wallaby-em

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71191.json"