CVE-2026-97404

Source
https://cve.org/CVERecord?id=CVE-2026-97404
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97404.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97404
Downstream
Published
2026-09-24T14:34:16Z
Modified
2026-10-03T03:46:42Z
Severity
  • 9.2 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
[none]
Details

In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticated remote attacker who knows a target project's UUID may bypass both Keystone authentication and pre-signed URL verification, resulting in the ability to read, enumerate, create, and delete that project's queues, messages, claims, and subscriptions. By additionally claiming an administrative role, the attacker may also perform administrative operations, such as managing pools and flavors in admin_mode deployments. Only deployments using the WSGI transport with an authentication strategy configured are affected; the websocket transport is not affected.

Database specific
{
    "cna_assigner": "mitre",
    "cwe_ids": [
        "CWE-348"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97404.json"
}
References

Affected packages

Git / opendev.org/openstack/zaqar

Affected ranges

Type
GIT
Repo
https://opendev.org/openstack/zaqar
Events
Introduced
45df812449070d4af489fed2cedf0fe84417d298
Fixed
be9c2e48c5799a35e3e2eacf1892e80e3ac6e37b
Introduced
245ab78e066f4224f54b477143651b20eab8d3e7
Fixed
d7d24bdebef2db0de987866b4a66ea12cbd28a20
Introduced
9e332b2b9364e0c113e35e158f7b500502ac629b
Fixed
b30f5cb937a9fbdeb469fd6bde23741de29565c5
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.0.0"
        },
        {
            "fixed": "20.1.2"
        },
        {
            "introduced": "21.0.0"
        },
        {
            "fixed": "21.0.2"
        },
        {
            "introduced": "22.0.0"
        },
        {
            "fixed": "22.0.2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

21.*
21.0.0
21.0.0.0rc1
21.0.1
22.*
22.0.0
22.0.0.0rc1
22.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97404.json"