USN-8814-1

Source
https://ubuntu.com/security/notices/USN-8814-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8814-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-8814-1
Upstream
CVE (3)
Related
Published
2026-09-24T12:38:30Z
Modified
2026-09-25T00:43:09Z
Summary
octavia vulnerabilities
Details

It was discovered that Octavia did not properly validate TLS cipher string fields in the Amphora provider driver. An authenticated attacker who owns a TLS-enabled load balancer could possibly use this issue to inject arbitrary HAProxy configuration directives. (CVE-2026-94572)

It was discovered that Octavia did not properly validate L7 policy redirect URL fields in the Amphora provider driver. An authenticated attacker who owns a load balancer could possibly use this issue to inject arbitrary HAProxy configuration directives. (CVE-2026-94571)

It was discovered that Octavia incorrectly handled quality of service policy authorization. An authenticated attacker could possibly use this issue to prevent deletion of another project's QoS policy. (CVE-2026-74248)

References

Affected packages

Ubuntu:22.04:LTS / octavia

Package

Name
octavia
Purl
pkg:deb/ubuntu/octavia?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1:10.1.1-0ubuntu1.5

Affected versions

1:9.*
1:9.0.0-0ubuntu1
1:9.0.0+git2021120816.ab3c3ef7-0ubuntu1
1:9.0.1+git2022011217.27e5b27d-0ubuntu1
1:9.0.1+git2022030314.328ffbab-0ubuntu1
1:10.*
1:10.0.0-0ubuntu1
1:10.1.0-0ubuntu1
1:10.1.1-0ubuntu1
1:10.1.1-0ubuntu1.1
1:10.1.1-0ubuntu1.2
1:10.1.1-0ubuntu1.3
1:10.1.1-0ubuntu1.4

Ecosystem specific

{
    "availability":  "No subscription required",
    "binaries":  [
        {
            "binary_name":  "amphora-agent",
            "binary_version":  "1:10.1.1-0ubuntu1.5"
        },
        {
            "binary_name":  "octavia-api",
            "binary_version":  "1:10.1.1-0ubuntu1.5"
        },
        {
            "binary_name":  "octavia-common",
            "binary_version":  "1:10.1.1-0ubuntu1.5"
        },
        {
            "binary_name":  "octavia-driver-agent",
            "binary_version":  "1:10.1.1-0ubuntu1.5"
        },
        {
            "binary_name":  "octavia-health-manager",
            "binary_version":  "1:10.1.1-0ubuntu1.5"
        },
        {
            "binary_name":  "octavia-housekeeping",
            "binary_version":  "1:10.1.1-0ubuntu1.5"
        },
        {
            "binary_name":  "octavia-worker",
            "binary_version":  "1:10.1.1-0ubuntu1.5"
        },
        {
            "binary_name":  "python3-octavia",
            "binary_version":  "1:10.1.1-0ubuntu1.5"
        }
    ]
}

Database specific

cves_map
{
    "cves":  [
        {
            "id":  "CVE-2026-74248",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-94571",
            "severity":  [
                {
                    "score":  "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                    "type":  "CVSS_V4"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-94572",
            "severity":  [
                {
                    "score":  "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                    "type":  "CVSS_V4"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem":  "Ubuntu:22.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8814-1.json"

Ubuntu:24.04:LTS / octavia

Package

Name
octavia
Purl
pkg:deb/ubuntu/octavia?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1:14.0.0-0ubuntu1.6

Affected versions

1:13.*
1:13.0.0-0ubuntu1
1:13.0.0+git2024011917.5750e451-0ubuntu1
1:14.*
1:14.0.0~rc1-0ubuntu1
1:14.0.0-0ubuntu1
1:14.0.0-0ubuntu1.1
1:14.0.0-0ubuntu1.2
1:14.0.0-0ubuntu1.3
1:14.0.0-0ubuntu1.4
1:14.0.0-0ubuntu1.5

Ecosystem specific

{
    "availability":  "No subscription required",
    "binaries":  [
        {
            "binary_name":  "amphora-agent",
            "binary_version":  "1:14.0.0-0ubuntu1.6"
        },
        {
            "binary_name":  "octavia-api",
            "binary_version":  "1:14.0.0-0ubuntu1.6"
        },
        {
            "binary_name":  "octavia-common",
            "binary_version":  "1:14.0.0-0ubuntu1.6"
        },
        {
            "binary_name":  "octavia-driver-agent",
            "binary_version":  "1:14.0.0-0ubuntu1.6"
        },
        {
            "binary_name":  "octavia-health-manager",
            "binary_version":  "1:14.0.0-0ubuntu1.6"
        },
        {
            "binary_name":  "octavia-housekeeping",
            "binary_version":  "1:14.0.0-0ubuntu1.6"
        },
        {
            "binary_name":  "octavia-worker",
            "binary_version":  "1:14.0.0-0ubuntu1.6"
        },
        {
            "binary_name":  "python3-octavia",
            "binary_version":  "1:14.0.0-0ubuntu1.6"
        }
    ]
}

Database specific

cves_map
{
    "cves":  [
        {
            "id":  "CVE-2026-74248",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-94571",
            "severity":  [
                {
                    "score":  "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                    "type":  "CVSS_V4"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-94572",
            "severity":  [
                {
                    "score":  "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                    "type":  "CVSS_V4"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem":  "Ubuntu:24.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8814-1.json"

Ubuntu:26.04:LTS / octavia

Package

Name
octavia
Purl
pkg:deb/ubuntu/octavia?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1:18.0.0-0ubuntu2.1

Affected versions

1:17.*
1:17.0.0-0ubuntu1
1:17.0.0+git20260116.e805a93-0ubuntu1
1:18.*
1:18.0.0~rc1-0ubuntu2
1:18.0.0-0ubuntu1
1:18.0.0-0ubuntu2

Ecosystem specific

{
    "availability":  "No subscription required",
    "binaries":  [
        {
            "binary_name":  "amphora-agent",
            "binary_version":  "1:18.0.0-0ubuntu2.1"
        },
        {
            "binary_name":  "octavia-api",
            "binary_version":  "1:18.0.0-0ubuntu2.1"
        },
        {
            "binary_name":  "octavia-common",
            "binary_version":  "1:18.0.0-0ubuntu2.1"
        },
        {
            "binary_name":  "octavia-driver-agent",
            "binary_version":  "1:18.0.0-0ubuntu2.1"
        },
        {
            "binary_name":  "octavia-health-manager",
            "binary_version":  "1:18.0.0-0ubuntu2.1"
        },
        {
            "binary_name":  "octavia-housekeeping",
            "binary_version":  "1:18.0.0-0ubuntu2.1"
        },
        {
            "binary_name":  "octavia-worker",
            "binary_version":  "1:18.0.0-0ubuntu2.1"
        },
        {
            "binary_name":  "python3-octavia",
            "binary_version":  "1:18.0.0-0ubuntu2.1"
        }
    ]
}

Database specific

cves_map
{
    "cves":  [
        {
            "id":  "CVE-2026-74248",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-94571",
            "severity":  [
                {
                    "score":  "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                    "type":  "CVSS_V4"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-94572",
            "severity":  [
                {
                    "score":  "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                    "type":  "CVSS_V4"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem":  "Ubuntu:26.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8814-1.json"