horizon
OpenStack Dashboard
Activity
- Latest release
- 2mo ago
- Total releases
- 107
- Cadence
- ~31 days
- Last 12 months
- 9
Details
- License
- Apache-2.0
- First release
- Jan 16, 2018
| Version | Released | |
|---|---|---|
26.0.0
major
1 CVE
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
26.0.0
major
Dependencies (57)
+ 49 more |
|
25.7.3
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
25.7.3
patch
Dependencies (58)
+ 50 more |
|
25.7.2
patch
3 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-43002
PYSEC-2026-2520
GHSA-vxvf-xvm3-p8j5
Jul 13, 2026
OpenStack Horizon has Incorrect Behavior Order
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix. Affected versions
25.6.0
25.7.0
25.7.1
25.7.2
Fixed in
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
25.7.2
patch
Dependencies (59)
+ 51 more |
|
25.7.1
patch
3 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-43002
PYSEC-2026-2520
GHSA-vxvf-xvm3-p8j5
Jul 13, 2026
OpenStack Horizon has Incorrect Behavior Order
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix. Affected versions
25.6.0
25.7.0
25.7.1
25.7.2
Fixed in
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
25.7.1
patch
Dependencies (59)
+ 51 more |
|
25.5.2
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
25.5.2
patch
Dependencies (59)
+ 51 more |
|
25.3.2
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
25.3.2
patch
Dependencies (57)
+ 49 more |
|
25.1.2
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
25.1.2
patch
Dependencies (58)
+ 50 more |
|
25.7.0
minor
3 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-43002
PYSEC-2026-2520
GHSA-vxvf-xvm3-p8j5
Jul 13, 2026
OpenStack Horizon has Incorrect Behavior Order
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix. Affected versions
25.6.0
25.7.0
25.7.1
25.7.2
Fixed in
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
25.7.0
minor
Dependencies (59)
+ 51 more |
|
25.6.0
minor
3 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-43002
PYSEC-2026-2520
GHSA-vxvf-xvm3-p8j5
Jul 13, 2026
OpenStack Horizon has Incorrect Behavior Order
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix. Affected versions
25.6.0
25.7.0
25.7.1
25.7.2
Fixed in
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
25.6.0
minor
Dependencies (59)
+ 51 more |
|
25.5.1
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
25.5.1
patch
Dependencies (59)
+ 51 more |
|
25.5.0
minor
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
25.5.0
minor
Dependencies (59)
+ 51 more |
|
24.0.2
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
24.0.2
patch
Dependencies (60)
+ 52 more |
|
25.1.1
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
25.1.1
patch
Dependencies (58)
+ 50 more |
|
25.3.1
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
25.3.1
patch
Dependencies (57)
+ 49 more |
|
24.0.1
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
24.0.1
patch
Dependencies (60)
+ 52 more |
|
25.4.0
minor
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
25.4.0
minor
Dependencies (57)
+ 49 more |
|
23.3.1
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
23.3.1
patch
Dependencies (61)
+ 53 more |
|
25.3.0
minor
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
25.3.0
minor
Dependencies (57)
+ 49 more |
|
25.2.0
minor
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
25.2.0
minor
Dependencies (57)
+ 49 more |
|
25.1.0
minor
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
25.1.0
minor
Dependencies (58)
+ 50 more |
|
23.1.1
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
23.1.1
patch
Dependencies (61)
+ 53 more |
|
25.0.0
major
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
25.0.0
major
Dependencies (58)
+ 50 more |
|
23.0.2
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
23.0.2
patch
Dependencies (61)
+ 53 more |
|
24.0.0
major
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
24.0.0
major
Dependencies (60)
+ 52 more |
|
23.0.1
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
23.0.1
patch
Dependencies (61)
+ 53 more |
|
23.4.0
minor
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
23.4.0
minor
Dependencies (61)
+ 53 more |
|
23.3.0
minor
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
23.3.0
minor
Dependencies (61)
+ 53 more |
|
22.1.1
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
22.1.1
patch
Dependencies (61)
+ 53 more |
|
23.2.0
minor
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
23.2.0
minor
Dependencies (61)
+ 53 more |
|
20.1.4
patch
3 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-45582
GHSA-5pv6-rprw-82wv
PYSEC-2023-153
Aug 22, 2023
Horizon Web Dashboard Open Redirect vulnerability
Medium
Network
Low
None
Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter. Affected versions
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
Fixed in
20.2.0
References
Updated Sep 20, 2024 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
20.1.4
patch
Dependencies (61)
+ 53 more |
|
23.1.0
minor
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
23.1.0
minor
Dependencies (61)
+ 53 more |
|
20.1.3
patch
3 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-45582
GHSA-5pv6-rprw-82wv
PYSEC-2023-153
Aug 22, 2023
Horizon Web Dashboard Open Redirect vulnerability
Medium
Network
Low
None
Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter. Affected versions
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
Fixed in
20.2.0
References
Updated Sep 20, 2024 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
20.1.3
patch
Dependencies (61)
+ 53 more |
|
19.4.0
minor
3 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-45582
GHSA-5pv6-rprw-82wv
PYSEC-2023-153
Aug 22, 2023
Horizon Web Dashboard Open Redirect vulnerability
Medium
Network
Low
None
Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter. Affected versions
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
Fixed in
20.2.0
References
Updated Sep 20, 2024 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
19.4.0
minor
Dependencies (60)
+ 52 more |
|
23.0.0
major
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
23.0.0
major
Dependencies (61)
+ 53 more |
|
19.3.0
minor
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
19.3.0
minor
Dependencies (60)
+ 52 more |
|
22.2.0
minor
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
22.2.0
minor
Dependencies (61)
+ 53 more |
|
20.1.2
patch
3 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-45582
GHSA-5pv6-rprw-82wv
PYSEC-2023-153
Aug 22, 2023
Horizon Web Dashboard Open Redirect vulnerability
Medium
Network
Low
None
Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter. Affected versions
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
Fixed in
20.2.0
References
Updated Sep 20, 2024 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
20.1.2
patch
Dependencies (61)
+ 53 more |
|
18.6.4
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
18.6.4
patch
Dependencies (60)
+ 52 more |
|
22.1.0
minor
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
22.1.0
minor
Dependencies (61)
+ 53 more |
|
22.0.0
major
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
22.0.0
major
Dependencies (61)
+ 53 more |
|
20.1.1
patch
3 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-45582
GHSA-5pv6-rprw-82wv
PYSEC-2023-153
Aug 22, 2023
Horizon Web Dashboard Open Redirect vulnerability
Medium
Network
Low
None
Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter. Affected versions
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
Fixed in
20.2.0
References
Updated Sep 20, 2024 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
20.1.1
patch
Dependencies (61)
+ 53 more |
|
21.0.0
major
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
21.0.0
major
Dependencies (61)
+ 53 more |
|
18.6.3
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
18.6.3
patch
Dependencies (60)
+ 52 more |
|
18.3.5
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
18.3.5
patch
Dependencies (60)
+ 52 more |
|
20.2.0
minor
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
20.2.0
minor
Dependencies (61)
+ 53 more |
|
20.1.0
minor
3 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-45582
GHSA-5pv6-rprw-82wv
PYSEC-2023-153
Aug 22, 2023
Horizon Web Dashboard Open Redirect vulnerability
Medium
Network
Low
None
Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter. Affected versions
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
Fixed in
20.2.0
References
Updated Sep 20, 2024 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
20.1.0
minor
Dependencies (61)
+ 53 more |
|
18.3.4
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
18.3.4
patch
Dependencies (60)
+ 52 more |
|
20.0.0
major
3 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-45582
GHSA-5pv6-rprw-82wv
PYSEC-2023-153
Aug 22, 2023
Horizon Web Dashboard Open Redirect vulnerability
Medium
Network
Low
None
Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter. Affected versions
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
Fixed in
20.2.0
References
Updated Sep 20, 2024 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
20.0.0
major
Dependencies (60)
+ 52 more |
|
16.2.2
patch
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
16.2.2
patch
Dependencies (61)
+ 53 more |
|
19.2.0
minor
2 CVEs
CVE-2026-55748
PYSEC-2026-2519
GHSA-6wrm-x65g-hr4p
Jul 13, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
6.0
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
Low
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 94 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.0.1
23.0.2
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.1.2
25.2.0
25.3.0
25.3.1
25.3.2
25.4.0
25.5.0
25.5.1
25.5.2
25.6.0
25.7.0
25.7.1
25.7.2
25.7.3
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-3540
PYSEC-2012-18
Sep 05, 2012
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake. Affected versions
12.0.2
12.0.3
12.0.4
13.0.0
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
14.0.0
14.0.0.0b1
+ 86 more Show less
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
15.0.0
15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1
15.3.2
16.0.0
16.0.0.0b1
16.0.0.0b2
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.2.1
16.2.2
17.0.0
17.1.0
18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.3.3
18.3.4
18.3.5
18.4.0
18.4.1
18.5.0
18.6.0
18.6.1
18.6.2
18.6.3
18.6.4
19.0.0
19.1.0
19.2.0
19.3.0
19.4.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.1.4
20.2.0
21.0.0
22.0.0
22.1.0
22.1.1
22.2.0
23.0.0
23.1.0
23.2.0
23.3.0
23.0.1
23.0.2
23.1.1
23.3.1
23.4.0
24.0.0
24.0.1
24.0.2
25.0.0
25.1.0
25.1.1
25.2.0
25.3.0
25.3.1
25.4.0
25.5.0
25.5.1
References
Updated Oct 09, 2025 · Source: OSV.dev |
19.2.0
minor
Dependencies (60)
+ 52 more |