GHSA-vxvf-xvm3-p8j5

Suggest an improvement
Source
https://github.com/advisories/GHSA-vxvf-xvm3-p8j5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-vxvf-xvm3-p8j5/GHSA-vxvf-xvm3-p8j5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vxvf-xvm3-p8j5
Aliases
Published
2026-05-05T18:33:27Z
Modified
2026-07-13T16:43:40Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
OpenStack Horizon has Incorrect Behavior Order
Details

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.

Database specific
{
    "cwe_ids":  [
        "CWE-696"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-08T22:19:51Z",
    "nvd_published_at":  "2026-05-05T17:17:04Z",
    "severity":  "MODERATE"
}
References

Affected packages

PyPI / horizon

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
25.6
Fixed
25.7.3

Affected versions

25.*
25.6.0
25.7.0
25.7.1
25.7.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-vxvf-xvm3-p8j5/GHSA-vxvf-xvm3-p8j5.json"