CVE-2026-71192

Source
https://cve.org/CVERecord?id=CVE-2026-71192
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71192.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-71192
Downstream
Published
2026-08-05T05:05:33.267Z
Modified
2026-08-25T04:02:29.705995004Z
Severity
  • 6.0 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
[none]
Details

In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3acl=true. An attacker can inject these headers into a signed PUT request targeting their own bucket, causing Swift to perform a server-side copy from another tenant's private object. The source object authorization is bypassed because the S3API middleware has already authorized the request against the destination. The attacker can read any object whose projectid, container name, and object name are known, regardless of the source object's ACLs or ownership. This requires the non-default s3_acl=true configuration.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71192.json",
    "cwe_ids": [
        "CWE-863"
    ],
    "cna_assigner": "mitre"
}
References

Affected packages

Git / opendev.org/openstack/swift

Affected ranges

Type
GIT
Repo
https://opendev.org/openstack/swift
Events
Introduced
f270466de363499894317b7c671f65e8a912bd53
Fixed
fc875f93e82edf98805d0eead3e3c961673c3ef8
Introduced
82cb5a5d78b91c6af258cd8f06d30f69be90fa18
Fixed
deaa3e4691bb19224f5ef57e7fbcd08b7eff5277
Introduced
555026d200337b39c97eb9dafd26901ff40c7a1d
Fixed
5104042f12efcaf90c28b656a378da8959004826
Introduced
9f5881d5143fd06a328bde2713cd9c61df579289
Last affected
9f5881d5143fd06a328bde2713cd9c61df579289
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "2.18.0"
        },
        {
            "fixed": "2.35.4"
        },
        {
            "introduced": "2.36.0"
        },
        {
            "fixed": "2.36.3"
        },
        {
            "introduced": "2.37.0"
        },
        {
            "fixed": "2.37.3"
        },
        {
            "introduced": "2.38.0"
        },
        {
            "last_affected": "2.38.0"
        }
    ]
}

Affected versions

2.*
2.18.0
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.25.0
2.26.0
2.27.0
2.28.0
2.29.0
2.29.1
2.30.0
2.31.0
2.31.1
2.32.0
2.33.0
2.34.0
2.35.0
2.35.1
2.35.2
2.35.3
2.36.0
2.36.1
2.36.2
2.37.0
2.37.1
2.37.2
2.38.0
Other
victoria-em
wallaby-em

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71192.json"