GHSA-9hfw-w3f4-c4p8

Suggest an improvement
Source
https://github.com/advisories/GHSA-9hfw-w3f4-c4p8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-9hfw-w3f4-c4p8/GHSA-9hfw-w3f4-c4p8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9hfw-w3f4-c4p8
Aliases
Published
2026-06-04T06:30:25Z
Modified
2026-07-23T15:11:42Z
Severity
  • 9.9 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed
Details

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

Database specific
{
    "cwe_ids":  [
        "CWE-749",
        "CWE-863"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-14T19:45:28Z",
    "nvd_published_at":  "2026-06-04T04:17:12Z",
    "severity":  "CRITICAL"
}
References

Affected packages

PyPI / mistral

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
20.0.0
Fixed
20.1.1

Affected versions

20.*
20.0.0
20.1.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-9hfw-w3f4-c4p8/GHSA-9hfw-w3f4-c4p8.json"

PyPI / mistral

Package

Affected ranges

Affected versions

21.*
21.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-9hfw-w3f4-c4p8/GHSA-9hfw-w3f4-c4p8.json"

PyPI / mistral

Package

Affected ranges

Affected versions

22.*
22.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-9hfw-w3f4-c4p8/GHSA-9hfw-w3f4-c4p8.json"