DEBIAN-CVE-2026-97404

Source
https://security-tracker.debian.org/tracker/CVE-2026-97404
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-97404.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-97404
Upstream
  • CVE-2026-97404
Published
2026-09-24T15:18:01Z
Modified
2026-09-25T05:00:44Z
Severity
  • 9.2 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticated remote attacker who knows a target project's UUID may bypass both Keystone authentication and pre-signed URL verification, resulting in the ability to read, enumerate, create, and delete that project's queues, messages, claims, and subscriptions. By additionally claiming an administrative role, the attacker may also perform administrative operations, such as managing pools and flavors in admin_mode deployments. Only deployments using the WSGI transport with an authentication strategy configured are affected; the websocket transport is not affected.

References

Affected packages

Debian:12 / zaqar

Package

Name
zaqar
Purl
pkg:deb/debian/zaqar?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

15.*
15.0.0-1
16.*
16.0.0~rc1-1
16.0.0-1
16.0.0-2
16.0.0-3
17.*
17.0.0~rc1-1
17.0.0-1
18.*
18.0.0~rc1-1
18.0.0-1
19.*
19.0.0~rc1-1
19.0.0~rc1-2
19.0.0-1
19.0.0-2
19.0.0-3
19.0.0-4
20.*
20.0.0~rc1-1
20.0.0~rc1-2
20.0.0-1
20.0.0-2
21.*
21.0.0~rc1-1
21.0.0~rc1-2
21.0.0-1
21.0.0-2
22.*
22.0.0~rc1-1
22.0.0~rc1-2
22.0.0-1
22.0.0-2
22.0.0-3
22.0.1-1
23.*
23.0.0~rc1-1
23.0.0~rc1-2
23.0.0~rc1-3

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-97404.json"

Debian:13 / zaqar

Package

Name
zaqar
Purl
pkg:deb/debian/zaqar?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

20.*
20.0.0-2
21.*
21.0.0~rc1-1
21.0.0~rc1-2
21.0.0-1
21.0.0-2
22.*
22.0.0~rc1-1
22.0.0~rc1-2
22.0.0-1
22.0.0-2
22.0.0-3
22.0.1-1
23.*
23.0.0~rc1-1
23.0.0~rc1-2
23.0.0~rc1-3

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-97404.json"

Debian:14 / zaqar

Package

Name
zaqar
Purl
pkg:deb/debian/zaqar?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

20.*
20.0.0-2
21.*
21.0.0~rc1-1
21.0.0~rc1-2
21.0.0-1
21.0.0-2
22.*
22.0.0~rc1-1
22.0.0~rc1-2
22.0.0-1
22.0.0-2
22.0.0-3
22.0.1-1
23.*
23.0.0~rc1-1
23.0.0~rc1-2
23.0.0~rc1-3

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-97404.json"