barbican
Service for storing sensitive client information for OpenStack
Activity
- Latest release
- 3d ago
- Total releases
- 47
- Cadence
- ~19 days
- Last 12 months
- 4
Details
- License
- Apache-2.0
- First release
- Oct 25, 2017
| Version | Released | |
|---|---|---|
23.0.0.0rc1
pre
|
23.0.0.0rc1
pre
Dependencies (30)
+ 22 more |
|
22.0.0
major
|
22.0.0
major
Dependencies (43)
+ 35 more |
|
22.0.0.0rc1
pre
|
22.0.0.0rc1
pre
Dependencies (43)
+ 35 more |
|
21.0.0
major
|
21.0.0
major
Dependencies (43)
+ 35 more |
|
21.0.0.0rc1
pre
|
21.0.0.0rc1
pre
Dependencies (43)
+ 35 more |
|
20.0.0
major
|
20.0.0
major
Dependencies (45)
+ 37 more |
|
20.0.0.0rc1
pre
|
20.0.0.0rc1
pre
Dependencies (45)
+ 37 more |
|
16.0.2
patch
|
16.0.2
patch
Dependencies (46)
+ 38 more |
|
19.0.0
major
|
19.0.0
major
Dependencies (45)
+ 37 more |
|
16.0.1
patch
|
16.0.1
patch
Dependencies (46)
+ 38 more |
|
19.0.0.0rc1
pre
|
19.0.0.0rc1
pre
Dependencies (45)
+ 37 more |
|
18.0.0
major
|
18.0.0
major
Dependencies (46)
+ 38 more |
|
18.0.0.0rc1
pre
|
18.0.0.0rc1
pre
Dependencies (46)
+ 38 more |
|
17.0.0
major
|
17.0.0
major
Dependencies (46)
+ 38 more |
|
17.0.0.0rc1
pre
|
17.0.0.0rc1
pre
Dependencies (46)
+ 38 more |
|
16.0.0
major
2 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev |
16.0.0
major
Dependencies (46)
+ 38 more |
|
16.0.0.0rc1
pre
2 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev |
16.0.0.0rc1
pre
Dependencies (46)
+ 38 more |
|
13.0.2
patch
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
13.0.2
patch
Dependencies (46)
+ 38 more |
|
14.0.2
patch
2 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev |
14.0.2
patch
Dependencies (46)
+ 38 more |
|
15.0.1
patch
2 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev |
15.0.1
patch
Dependencies (47)
+ 39 more |
|
12.0.2
patch
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
12.0.2
patch
Dependencies (46)
+ 38 more |
|
13.0.1
patch
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
13.0.1
patch
Dependencies (46)
+ 38 more |
|
14.0.1
patch
2 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev |
14.0.1
patch
Dependencies (46)
+ 38 more |
|
15.0.0
major
2 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev |
15.0.0
major
Dependencies (47)
+ 39 more |
|
15.0.0.0rc3
pre
2 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev |
15.0.0.0rc3
pre
Dependencies (47)
+ 39 more |
|
15.0.0.0rc2
pre
2 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev |
15.0.0.0rc2
pre
Dependencies (47)
+ 39 more |
|
15.0.0.0rc1
pre
2 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev |
15.0.0.0rc1
pre
Dependencies (47)
+ 39 more |
|
12.0.1
patch
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
12.0.1
patch
Dependencies (46)
+ 38 more |
|
14.0.0
major
2 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev |
14.0.0
major
Dependencies (46)
+ 38 more |
|
14.0.0.0rc1
pre
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
14.0.0.0rc1
pre
Dependencies (46)
+ 38 more |
|
13.0.0
major
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
13.0.0
major
Dependencies (46)
+ 38 more |
|
13.0.0.0rc1
pre
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
13.0.0.0rc1
pre
Dependencies (46)
+ 38 more |
|
10.1.0
minor
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
10.1.0
minor
Dependencies (48)
+ 40 more |
|
12.0.0
major
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
12.0.0
major
Dependencies (46)
+ 38 more |
|
12.0.0.0rc2
pre
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
12.0.0.0rc2
pre
Dependencies (46)
+ 38 more |
|
12.0.0.0rc1
pre
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
12.0.0.0rc1
pre
Dependencies (46)
+ 38 more |
|
11.0.0
major
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
11.0.0
major
Dependencies (47)
+ 39 more |
|
11.0.0.0rc1
pre
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
11.0.0.0rc1
pre
Dependencies (47)
+ 39 more |
|
8.0.1
patch
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
8.0.1
patch
Dependencies (48)
+ 40 more |
|
9.0.1
patch
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
9.0.1
patch
Dependencies (48)
+ 40 more |
|
10.0.0
major
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
10.0.0
major
Dependencies (48)
+ 40 more |
|
10.0.0.0rc1
pre
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
10.0.0.0rc1
pre
Dependencies (48)
+ 40 more |
|
9.0.0
major
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
9.0.0
major
Dependencies (48)
+ 40 more |
|
9.0.0.0rc1
pre
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
9.0.0.0rc1
pre
Dependencies (48)
+ 40 more |
|
8.0.0
initial
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
8.0.0
initial
Dependencies (48)
+ 40 more |
|
8.0.0.0rc1
pre
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
8.0.0.0rc1
pre
Dependencies (48)
+ 40 more |
|
6.0.0.0b1
pre
4 CVEs
CVE-2023-1633
PYSEC-2026-1213
GHSA-6qqp-4vm3-359v
Jul 07, 2026
OpenStack Barbican credential leak flaw
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
High
Low
Low
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-1636
PYSEC-2026-1214
GHSA-6rx9-c2rh-3qv4
Jul 07, 2026
OpenStack Barbican information disclosure vulnerability
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 21 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0
14.0.0.0rc1
14.0.1
14.0.2
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.0.0rc3
15.0.1
16.0.0
16.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23451
PYSEC-2026-786
GHSA-p2jg-q8hw-p7gc
Jul 06, 2026
Barbican authorization flaw before v14.0.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-23452
PYSEC-2026-785
GHSA-6p2h-rjj7-2j63
Jul 06, 2026
openstack-barbican Denial of Service vulnerability
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. Affected versions
0
10.0.0
10.0.0.0rc1
10.1.0
11.0.0
11.0.0.0rc1
12.0.0
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
13.0.0
+ 11 more Show less
13.0.0.0rc1
13.0.1
13.0.2
14.0.0.0rc1
6.0.0.0b1
8.0.0
8.0.0.0rc1
8.0.1
9.0.0
9.0.0.0rc1
9.0.1
Fixed in
14.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.0.0.0b1
pre
Dependencies (30)
+ 22 more |