cinder
OpenStack Block Storage
Activity
- Latest release
- 3d ago
- Total releases
- 137
- Cadence
- ~9 days
- Last 12 months
- 10
Details
- License
- Apache-2.0
- First release
- Oct 02, 2018
| Version | Released | |
|---|---|---|
29.0.0.0rc1
pre
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
29.0.0.0rc1
pre
Dependencies (76)
+ 68 more |
|
26.3.0
minor
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
26.3.0
minor
Dependencies (88)
+ 80 more |
|
28.0.0
major
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
28.0.0
major
Dependencies (73)
+ 65 more |
|
28.0.0.0rc2
pre
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
28.0.0.0rc2
pre
Dependencies (73)
+ 65 more |
|
28.0.0.0rc1
pre
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
28.0.0.0rc1
pre
Dependencies (73)
+ 65 more |
|
25.3.1
patch
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
25.3.1
patch
Dependencies (89)
+ 81 more |
|
26.2.0
minor
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
26.2.0
minor
Dependencies (88)
+ 80 more |
|
24.5.0
minor
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
24.5.0
minor
Dependencies (91)
+ 83 more |
|
25.3.0
minor
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
25.3.0
minor
Dependencies (89)
+ 81 more |
|
27.0.0
major
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
27.0.0
major
Dependencies (88)
+ 80 more |
|
27.0.0.0rc1
pre
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
27.0.0.0rc1
pre
Dependencies (88)
+ 80 more |
|
26.1.0
minor
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
26.1.0
minor
Dependencies (88)
+ 80 more |
|
25.2.0
minor
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
25.2.0
minor
Dependencies (89)
+ 81 more |
|
24.4.0
minor
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
24.4.0
minor
Dependencies (91)
+ 83 more |
|
23.5.0
minor
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
23.5.0
minor
Dependencies (91)
+ 83 more |
|
26.0.0
major
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
26.0.0
major
Dependencies (88)
+ 80 more |
|
26.0.0.0rc2
pre
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
26.0.0.0rc2
pre
Dependencies (88)
+ 80 more |
|
26.0.0.0rc1
pre
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
26.0.0.0rc1
pre
Dependencies (88)
+ 80 more |
|
23.4.0
minor
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
23.4.0
minor
Dependencies (91)
+ 83 more |
|
24.3.0
minor
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
24.3.0
minor
Dependencies (91)
+ 83 more |
|
25.1.0
minor
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
25.1.0
minor
Dependencies (89)
+ 81 more |
|
23.3.0
minor
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
23.3.0
minor
Dependencies (91)
+ 83 more |
|
24.2.0
minor
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
24.2.0
minor
Dependencies (91)
+ 83 more |
|
22.3.0
minor
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
22.3.0
minor
Dependencies (92)
+ 84 more |
|
25.0.0
major
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
25.0.0
major
Dependencies (89)
+ 81 more |
|
25.0.0.0rc2
pre
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
25.0.0.0rc2
pre
Dependencies (89)
+ 81 more |
|
25.0.0.0rc1
pre
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
25.0.0.0rc1
pre
Dependencies (89)
+ 81 more |
|
23.2.0
minor
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
23.2.0
minor
Dependencies (91)
+ 83 more |
|
22.2.0
minor
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
22.2.0
minor
Dependencies (92)
+ 84 more |
|
24.1.0
minor
1 CVE
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
24.1.0
minor
Dependencies (91)
+ 83 more |
|
22.1.2
patch
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
22.1.2
patch
Dependencies (92)
+ 84 more |
|
24.0.0
major
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
24.0.0
major
Dependencies (91)
+ 83 more |
|
24.0.0.0rc2
pre
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
24.0.0.0rc2
pre
Dependencies (91)
+ 83 more |
|
24.0.0.0rc1
pre
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
24.0.0.0rc1
pre
Dependencies (91)
+ 83 more |
|
21.3.2
patch
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
21.3.2
patch
Dependencies (91)
+ 83 more |
|
23.1.0
minor
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
23.1.0
minor
Dependencies (91)
+ 83 more |
|
20.3.2
patch
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
20.3.2
patch
Dependencies (92)
+ 84 more |
|
23.0.0
major
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
23.0.0
major
Dependencies (91)
+ 83 more |
|
23.0.0.0rc2
pre
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
23.0.0.0rc2
pre
Dependencies (91)
+ 83 more |
|
23.0.0.0rc1
pre
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
23.0.0.0rc1
pre
Dependencies (91)
+ 83 more |
|
22.1.1
patch
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
22.1.1
patch
Dependencies (92)
+ 84 more |
|
21.3.1
patch
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
21.3.1
patch
Dependencies (91)
+ 83 more |
|
20.3.1
patch
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
20.3.1
patch
Dependencies (92)
+ 84 more |
|
21.3.0
minor
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
21.3.0
minor
Dependencies (91)
+ 83 more |
|
22.1.0
minor
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
22.1.0
minor
Dependencies (92)
+ 84 more |
|
20.3.0
minor
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
20.3.0
minor
Dependencies (92)
+ 84 more |
|
20.2.0
minor
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
20.2.0
minor
Dependencies (92)
+ 84 more |
|
21.2.0
minor
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
21.2.0
minor
Dependencies (91)
+ 83 more |
|
19.3.0
minor
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
19.3.0
minor
Dependencies (92)
+ 84 more |
|
22.0.0
major
2 CVEs
CVE-2024-32498
PYSEC-2026-2414
GHSA-r4v4-w9pv-6fph
PYSEC-2026-1708
PYSEC-2026-2493
Jul 13, 2026
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
Network
Low
Low
None
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 101 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2014-3641
PYSEC-2026-791
GHSA-qhch-g8qr-p497
Jul 06, 2026
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. Affected versions
10.0.8
11.2.0
11.2.1
11.2.2
12.0.10
12.0.4
12.0.5
12.0.6
12.0.7
12.0.8
12.0.9
13.0.1
+ 124 more Show less
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
13.0.8
13.0.9
14.0.0
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.2.1
14.3.0
14.3.1
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.1.0
15.2.0
15.3.0
15.4.0
15.4.1
15.5.0
15.6.0
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.0.0.0rc3
16.1.0
16.2.0
16.2.1
16.3.0
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
17.1.0
17.2.0
17.3.0
17.4.0
18.0.0
18.0.0.0b1
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.2.0
18.2.1
19.0.0
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.1.1
19.2.0
19.3.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1
20.3.2
21.0.0
21.0.0.0rc2
21.1.0
21.2.0
21.3.0
21.3.1
21.3.2
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.1.0
22.1.1
22.1.2
22.2.0
22.3.0
23.0.0
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.3.0
24.4.0
24.5.0
25.0.0
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.3.0
25.3.1
26.0.0
26.0.0.0rc1
26.0.0.0rc2
26.1.0
26.2.0
26.3.0
27.0.0
27.0.0.0rc1
28.0.0
28.0.0.0rc1
28.0.0.0rc2
Fixed in
2014.1.3
References Updated Jul 20, 2026 · Source: OSV.dev |
22.0.0
major
Dependencies (92)
+ 84 more |