PYSEC-2026-3034

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/python-keystoneclient/PYSEC-2026-3034.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-3034
Aliases
Published
2026-07-09T16:49:45.351125Z
Modified
2026-07-13T16:43:08.272597925Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
OpenStack Keystone and other components vulnerable to Improper Certificate Validation
Details

HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.

References

Affected packages

PyPI / python-keystoneclient

Package

Name
python-keystoneclient
View open source insights on deps.dev
Purl
pkg:pypi/python-keystoneclient

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.4.0

Affected versions

0.*
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.3.0
0.3.1
0.3.2

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/python-keystoneclient/PYSEC-2026-3034.yaml"