keystone
OpenStack Identity
Activity
- Latest release
- 3h ago
- Total releases
- 68
- Cadence
- ~19 days
- Last 12 months
- 15
Details
- License
- Apache-2.0
- First release
- Oct 08, 2018
| Version | Released | |
|---|---|---|
30.0.0.0rc1
pre
2 CVEs
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
30.0.0.0rc1
pre
Dependencies (33)
+ 25 more |
|
29.1.0
minor
2 CVEs
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
29.1.0
minor
Dependencies (33)
+ 25 more |
|
28.1.0
minor
3 CVEs
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
28.1.0
minor
Dependencies (48)
+ 40 more |
|
27.1.0
minor
4 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
27.1.0
minor
Dependencies (47)
+ 39 more |
|
29.0.2
patch
2 CVEs
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
29.0.2
patch
Dependencies (33)
+ 25 more |
|
28.0.2
patch
3 CVEs
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
28.0.2
patch
Dependencies (48)
+ 40 more |
|
27.0.2
patch
4 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
27.0.2
patch
Dependencies (47)
+ 39 more |
|
29.0.1
patch
7 CVEs
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
29.0.1
patch
Dependencies (33)
+ 25 more |
|
26.1.1
patch
8 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
26.1.1
patch
Dependencies (49)
+ 41 more |
|
28.0.1
patch
7 CVEs
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
28.0.1
patch
Dependencies (48)
+ 40 more |
|
27.0.1
patch
8 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
27.0.1
patch
Dependencies (47)
+ 39 more |
|
29.0.0
major
7 CVEs
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
29.0.0
major
Dependencies (33)
+ 25 more |
|
29.0.0.0rc1
pre
3 CVEs
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
29.0.0.0rc1
pre
Dependencies (33)
+ 25 more |
|
26.1.0
minor
9 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
26.1.0
minor
Dependencies (49)
+ 41 more |
|
28.0.0
major
8 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
28.0.0
major
Dependencies (48)
+ 40 more |
|
28.0.0.0rc1
pre
5 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
28.0.0.0rc1
pre
Dependencies (48)
+ 40 more |
|
27.0.0
major
8 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
27.0.0
major
Dependencies (47)
+ 39 more |
|
27.0.0.0rc1
pre
9 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
27.0.0.0rc1
pre
Dependencies (47)
+ 39 more |
|
24.1.0
minor
10 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
24.1.0
minor
Dependencies (51)
+ 43 more |
|
26.0.0
major
10 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
26.0.0
major
Dependencies (49)
+ 41 more |
|
26.0.0.0rc1
pre
10 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
26.0.0.0rc1
pre
Dependencies (49)
+ 41 more |
|
23.0.2
patch
10 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
23.0.2
patch
Dependencies (52)
+ 44 more |
|
22.0.2
patch
10 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
22.0.2
patch
Dependencies (53)
+ 45 more |
|
25.0.0
major
10 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
25.0.0
major
Dependencies (50)
+ 42 more |
|
25.0.0.0rc1
pre
10 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
25.0.0.0rc1
pre
Dependencies (50)
+ 42 more |
|
21.0.1
patch
10 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
21.0.1
patch
Dependencies (53)
+ 45 more |
|
23.0.1
patch
10 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
23.0.1
patch
Dependencies (52)
+ 44 more |
|
22.0.1
patch
10 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
22.0.1
patch
Dependencies (53)
+ 45 more |
|
24.0.0
major
10 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
24.0.0
major
Dependencies (51)
+ 43 more |
|
24.0.0.0rc1
pre
10 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
24.0.0.0rc1
pre
Dependencies (51)
+ 43 more |
|
23.0.0
major
10 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
23.0.0
major
Dependencies (52)
+ 44 more |
|
23.0.0.0rc1
pre
10 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
23.0.0.0rc1
pre
Dependencies (52)
+ 44 more |
|
20.0.1
patch
11 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3563
PYSEC-2026-370
GHSA-cc99-whm5-mmq3
Jun 29, 2026
Openstack Keystone Incorrect Authorization vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A patch is available. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 22 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
20.0.1
patch
Dependencies (53)
+ 45 more |
|
22.0.0
major
10 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
22.0.0
major
Dependencies (53)
+ 45 more |
|
22.0.0.0rc1
pre
10 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
22.0.0.0rc1
pre
Dependencies (53)
+ 45 more |
|
19.0.1
patch
11 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3563
PYSEC-2026-370
GHSA-cc99-whm5-mmq3
Jun 29, 2026
Openstack Keystone Incorrect Authorization vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A patch is available. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 22 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
19.0.1
patch
Dependencies (53)
+ 45 more |
|
21.0.0
major
11 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3563
PYSEC-2026-370
GHSA-cc99-whm5-mmq3
Jun 29, 2026
Openstack Keystone Incorrect Authorization vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A patch is available. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 22 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
21.0.0
major
Dependencies (53)
+ 45 more |
|
21.0.0.0rc1
pre
11 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3563
PYSEC-2026-370
GHSA-cc99-whm5-mmq3
Jun 29, 2026
Openstack Keystone Incorrect Authorization vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A patch is available. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 22 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
21.0.0.0rc1
pre
Dependencies (53)
+ 45 more |
|
18.1.0
minor
11 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3563
PYSEC-2026-370
GHSA-cc99-whm5-mmq3
Jun 29, 2026
Openstack Keystone Incorrect Authorization vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A patch is available. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 22 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
18.1.0
minor
Dependencies (53)
+ 45 more |
|
20.0.0
major
11 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3563
PYSEC-2026-370
GHSA-cc99-whm5-mmq3
Jun 29, 2026
Openstack Keystone Incorrect Authorization vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A patch is available. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 22 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
20.0.0
major
Dependencies (53)
+ 45 more |
|
20.0.0.0rc1
pre
11 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3563
PYSEC-2026-370
GHSA-cc99-whm5-mmq3
Jun 29, 2026
Openstack Keystone Incorrect Authorization vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A patch is available. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 22 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
20.0.0.0rc1
pre
Dependencies (53)
+ 45 more |
|
17.0.1
patch
11 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3563
PYSEC-2026-370
GHSA-cc99-whm5-mmq3
Jun 29, 2026
Openstack Keystone Incorrect Authorization vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A patch is available. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 22 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
17.0.1
patch
Dependencies (54)
+ 46 more |
|
16.0.2
patch
11 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3563
PYSEC-2026-370
GHSA-cc99-whm5-mmq3
Jun 29, 2026
Openstack Keystone Incorrect Authorization vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A patch is available. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 22 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
16.0.2
patch
Dependencies (58)
+ 50 more |
|
19.0.0
major
12 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-38155
PYSEC-2026-830
GHSA-4225-97pr-rr52
Jul 06, 2026
OpenStack Keystone allows information disclosure during account locking
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could both confirm the account exists and obtain that account's corresponding UUID, which might be leveraged for other unrelated attacks. All deployments enabling security_compliance.lockout_failure_attempts are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 8 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
17.0.0
18.0.0
19.0.0
Fixed in
16.0.2
17.0.1
18.0.1
19.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3563
PYSEC-2026-370
GHSA-cc99-whm5-mmq3
Jun 29, 2026
Openstack Keystone Incorrect Authorization vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A patch is available. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 22 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
19.0.0
major
Dependencies (53)
+ 45 more |
|
19.0.0.0rc2
pre
11 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3563
PYSEC-2026-370
GHSA-cc99-whm5-mmq3
Jun 29, 2026
Openstack Keystone Incorrect Authorization vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A patch is available. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 22 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
19.0.0.0rc2
pre
Dependencies (53)
+ 45 more |
|
19.0.0.0rc1
pre
11 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3563
PYSEC-2026-370
GHSA-cc99-whm5-mmq3
Jun 29, 2026
Openstack Keystone Incorrect Authorization vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A patch is available. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 22 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
19.0.0.0rc1
pre
Dependencies (53)
+ 45 more |
|
18.0.0
major
12 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-38155
PYSEC-2026-830
GHSA-4225-97pr-rr52
Jul 06, 2026
OpenStack Keystone allows information disclosure during account locking
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could both confirm the account exists and obtain that account's corresponding UUID, which might be leveraged for other unrelated attacks. All deployments enabling security_compliance.lockout_failure_attempts are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 8 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
17.0.0
18.0.0
19.0.0
Fixed in
16.0.2
17.0.1
18.0.1
19.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3563
PYSEC-2026-370
GHSA-cc99-whm5-mmq3
Jun 29, 2026
Openstack Keystone Incorrect Authorization vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A patch is available. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 22 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
18.0.0
major
Dependencies (53)
+ 45 more |
|
18.0.0.0rc1
pre
11 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3563
PYSEC-2026-370
GHSA-cc99-whm5-mmq3
Jun 29, 2026
Openstack Keystone Incorrect Authorization vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A patch is available. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 22 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
18.0.0.0rc1
pre
Dependencies (53)
+ 45 more |
|
17.0.0
major
12 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-38155
PYSEC-2026-830
GHSA-4225-97pr-rr52
Jul 06, 2026
OpenStack Keystone allows information disclosure during account locking
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could both confirm the account exists and obtain that account's corresponding UUID, which might be leveraged for other unrelated attacks. All deployments enabling security_compliance.lockout_failure_attempts are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 8 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
17.0.0
18.0.0
19.0.0
Fixed in
16.0.2
17.0.1
18.0.1
19.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3563
PYSEC-2026-370
GHSA-cc99-whm5-mmq3
Jun 29, 2026
Openstack Keystone Incorrect Authorization vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A patch is available. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 22 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
17.0.0
major
Dependencies (54)
+ 46 more |
|
16.0.1
patch
12 CVEs
CVE-2026-40683
PYSEC-2026-2550
GHSA-pfx2-9x9m-7ghx
Jul 13, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
7.7
/ 10
High
Network
High
Low
None
Changed
Low
Low
High
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 46 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
Fixed in
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-65073
PYSEC-2026-1490
GHSA-hcqg-5g63-7j9h
Jul 07, 2026
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
7.5
/ 10
High
Network
High
None
None
Changed
Low
High
None
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 40 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
27.0.0.0rc1
28.0.0.0rc1
Fixed in
26.0.1
27.0.0
28.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-38155
PYSEC-2026-830
GHSA-4225-97pr-rr52
Jul 06, 2026
OpenStack Keystone allows information disclosure during account locking
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could both confirm the account exists and obtain that account's corresponding UUID, which might be leveraged for other unrelated attacks. All deployments enabling security_compliance.lockout_failure_attempts are affected. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 8 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
17.0.0
18.0.0
19.0.0
Fixed in
16.0.2
17.0.1
18.0.1
19.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2012-4413
PYSEC-2026-833
GHSA-mrxv-65rv-6hxq
Jul 06, 2026
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 52 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
Fixed in
2012.1.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3563
PYSEC-2026-370
GHSA-cc99-whm5-mmq3
Jun 29, 2026
Openstack Keystone Incorrect Authorization vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A patch is available. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 22 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-42998
GHSA-8f8m-wrvr-wcvf
PYSEC-2026-599
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43000
GHSA-q623-f4j4-p4xj
PYSEC-2026-601
May 28, 2026
OpenStack Keystone has an Incorrect Authorization issue
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42999
GHSA-2r23-2g6v-2m5f
PYSEC-2026-600
May 28, 2026
OpenStack Keystone has an Authorization Bypass
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0). Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44394
GHSA-whqr-fgm5-x77q
PYSEC-2026-603
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
6.0
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
Low
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 42 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
28.0.0
28.0.1
29.0.0
29.0.1
Fixed in
27.0.2
28.0.2
29.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-43001
GHSA-hhq2-3832-xxcv
PYSEC-2026-602
May 01, 2026
OpenStack Keystone has an Incorrect Authorization Issue
7.9
/ 10
High
Network
High
High
None
Changed
High
High
Low
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. Affected versions
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
+ 51 more Show less
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33551
GHSA-4phw-6824-6cfp
PYSEC-2026-202
Apr 10, 2026
OpenStack Keystone: Restricted application credentials can create EC2 credentials
3.5
/ 10
Low
Network
High
Low
None
Changed
None
Low
None
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected. Affected versions
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
+ 34 more Show less
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
Fixed in
26.1.1
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2012-3542
GHSA-gf2q-j2qq-pjf2
PYSEC-2012-19
May 17, 2022
OpenStack Keystone Allows Remote User Account Creation
High
Network
Low
None
None
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540. Affected versions
12.0.2
12.0.3
13.0.2
13.0.3
13.0.4
14.0.0
14.0.1
14.1.0
14.2.0
15.0.0
15.0.0.0rc1
15.0.0.0rc2
+ 55 more Show less
15.0.1
16.0.0
16.0.0.0rc1
16.0.0.0rc2
16.0.1
16.0.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.0.1
18.0.0
18.0.0.0rc1
18.1.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.0.1
20.0.0
20.0.0.0rc1
20.0.1
21.0.0
21.0.0.0rc1
21.0.1
22.0.0
22.0.0.0rc1
22.0.1
22.0.2
23.0.0
23.0.0.0rc1
23.0.1
23.0.2
24.0.0
24.0.0.0rc1
24.1.0
25.0.0
25.0.0.0rc1
26.0.0
26.0.0.0rc1
26.1.0
26.1.1
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.1.0
28.0.0
28.0.0.0rc1
28.0.1
28.0.2
28.1.0
29.0.0
29.0.0.0rc1
29.0.1
29.0.2
29.1.0
Fixed in
2012.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
16.0.1
patch
Dependencies (59)
+ 51 more |