DEBIAN-CVE-2026-43002

Source
https://security-tracker.debian.org/tracker/CVE-2026-43002
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-43002.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-43002
Upstream
Published
2026-05-05T17:17:04Z
Modified
2026-09-11T08:47:33Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
[none]
Details

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.

References

Affected packages

Debian:14 / horizon

Package

Name
horizon
Purl
pkg:deb/debian/horizon?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3:25.7.3-1

Affected versions

3:25.*
3:25.3.0-3
3:25.5.0-4
3:25.5.1-1
3:25.5.1-2
3:25.5.1-3
3:25.6.0-1
3:25.6.0-2
3:25.7.0-1
3:25.7.0-2
3:25.7.1-1
3:25.7.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-43002.json"