mistral
Mistral Project
Activity
- Latest release
- 6d ago
- Total releases
- 120
- Cadence
- ~18 days
- Last 12 months
- 5
Details
- License
- Apache-2.0
- First release
- Apr 30, 2014
| Version | Released | |
|---|---|---|
23.0.0.0rc1
pre
|
23.0.0.0rc1
pre
Dependencies (34)
+ 26 more |
|
22.0.0
major
1 CVE
CVE-2026-41283
PYSEC-2026-3486
GHSA-9hfw-w3f4-c4p8
Jul 23, 2026
OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials. Affected versions
20.0.0
20.1.0
21.0.0
22.0.0
Fixed in
20.1.1
References
Updated Jul 23, 2026 · Source: OSV.dev |
22.0.0
major
Dependencies (34)
+ 26 more |
|
22.0.0.0rc1
pre
|
22.0.0.0rc1
pre
Dependencies (34)
+ 26 more |
|
19.1.1
patch
|
19.1.1
patch
Dependencies (36)
+ 28 more |
|
21.0.0
major
1 CVE
CVE-2026-41283
PYSEC-2026-3486
GHSA-9hfw-w3f4-c4p8
Jul 23, 2026
OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials. Affected versions
20.0.0
20.1.0
21.0.0
22.0.0
Fixed in
20.1.1
References
Updated Jul 23, 2026 · Source: OSV.dev |
21.0.0
major
Dependencies (34)
+ 26 more |
|
21.0.0.0rc1
pre
|
21.0.0.0rc1
pre
Dependencies (34)
+ 26 more |
|
18.1.0
minor
|
18.1.0
minor
Dependencies (36)
+ 28 more |
|
19.1.0
minor
|
19.1.0
minor
Dependencies (36)
+ 28 more |
|
20.1.0
minor
1 CVE
CVE-2026-41283
PYSEC-2026-3486
GHSA-9hfw-w3f4-c4p8
Jul 23, 2026
OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials. Affected versions
20.0.0
20.1.0
21.0.0
22.0.0
Fixed in
20.1.1
References
Updated Jul 23, 2026 · Source: OSV.dev |
20.1.0
minor
Dependencies (36)
+ 28 more |
|
20.0.0
major
1 CVE
CVE-2026-41283
PYSEC-2026-3486
GHSA-9hfw-w3f4-c4p8
Jul 23, 2026
OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials. Affected versions
20.0.0
20.1.0
21.0.0
22.0.0
Fixed in
20.1.1
References
Updated Jul 23, 2026 · Source: OSV.dev |
20.0.0
major
Dependencies (36)
+ 28 more |
|
20.0.0.0rc1
pre
|
20.0.0.0rc1
pre
Dependencies (36)
+ 28 more |
|
19.0.0
major
|
19.0.0
major
Dependencies (36)
+ 28 more |
|
19.0.0.0rc1
pre
|
19.0.0.0rc1
pre
Dependencies (36)
+ 28 more |
|
18.0.1
patch
|
18.0.1
patch
Dependencies (36)
+ 28 more |
|
18.0.0
major
|
18.0.0
major
Dependencies (36)
+ 28 more |
|
18.0.0.0rc1
pre
|
18.0.0.0rc1
pre
Dependencies (36)
+ 28 more |
|
15.0.1
patch
|
15.0.1
patch
Dependencies (37)
+ 29 more |
|
17.0.0
major
|
17.0.0
major
Dependencies (37)
+ 29 more |
|
17.0.0.0rc1
pre
|
17.0.0.0rc1
pre
Dependencies (37)
+ 29 more |
|
16.0.0
major
|
16.0.0
major
Dependencies (37)
+ 29 more |
|
16.0.0.0rc1
pre
|
16.0.0.0rc1
pre
Dependencies (37)
+ 29 more |
|
16.0.0.0b1
pre
|
16.0.0.0b1
pre
Dependencies (37)
+ 29 more |
|
15.0.0
major
|
15.0.0
major
Dependencies (37)
+ 29 more |
|
15.0.0.0rc1
pre
|
15.0.0.0rc1
pre
Dependencies (37)
+ 29 more |
|
14.0.0
major
|
14.0.0
major
Dependencies (37)
+ 29 more |
|
14.0.0.0rc1
pre
|
14.0.0.0rc1
pre
Dependencies (37)
+ 29 more |
|
13.0.0
major
|
13.0.0
major
Dependencies (37)
+ 29 more |
|
13.0.0.0rc1
pre
|
13.0.0.0rc1
pre
Dependencies (37)
+ 29 more |
|
12.0.0
major
|
12.0.0
major
Dependencies (37)
+ 29 more |
|
12.0.0.0rc1
pre
|
12.0.0.0rc1
pre
Dependencies (37)
+ 29 more |
|
11.0.0
major
|
11.0.0
major
Dependencies (37)
+ 29 more |
|
11.0.0.0rc1
pre
|
11.0.0.0rc1
pre
Dependencies (37)
+ 29 more |
|
10.0.0
major
|
10.0.0
major
Dependencies (39)
+ 31 more |
|
10.0.0.0rc1
pre
1 CVE
CVE-2018-16848
GHSA-443j-6p7g-6v4w
PYSEC-2020-240
May 24, 2022
OpenStack Mistral DoS
High
Network
Low
Low
None
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service. Affected versions
0
0.0.1
0.0.2
0.0.3
0.0.4
0.1
0.1.1
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
+ 71 more Show less
1.0.0.0rc2
1.0.1
10.0.0.0b1
10.0.0.0b2
10.0.0.0b3
10.0.0.0rc1
2.0.0
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2.0.0.0rc2
2.0.0.0rc3
3.0.0.0b1
3.0.2
4.0.0
4.0.0.0b1
4.0.0.0b2
4.0.0.0b3
4.0.0.0rc1
4.0.0.0rc2
4.0.1
4.0.2
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.0.0b1
6.0.0.0b2
6.0.0.0b3
6.0.0.0rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
7.0.0
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
8.0.0
8.0.0.0b1
8.0.0.0b2
8.0.0.0rc1
8.0.0.0rc2
8.1.0
9.0.0
9.0.0.0b1
9.0.0.0rc1
9.0.0.0rc2
9.0.1
9.1.0
Fixed in
10.0.0
References
Updated Sep 25, 2024 · Source: OSV.dev |
10.0.0.0rc1
pre
Dependencies (39)
+ 31 more |
|
9.1.0
minor
1 CVE
CVE-2018-16848
GHSA-443j-6p7g-6v4w
PYSEC-2020-240
May 24, 2022
OpenStack Mistral DoS
High
Network
Low
Low
None
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service. Affected versions
0
0.0.1
0.0.2
0.0.3
0.0.4
0.1
0.1.1
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
+ 71 more Show less
1.0.0.0rc2
1.0.1
10.0.0.0b1
10.0.0.0b2
10.0.0.0b3
10.0.0.0rc1
2.0.0
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2.0.0.0rc2
2.0.0.0rc3
3.0.0.0b1
3.0.2
4.0.0
4.0.0.0b1
4.0.0.0b2
4.0.0.0b3
4.0.0.0rc1
4.0.0.0rc2
4.0.1
4.0.2
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.0.0b1
6.0.0.0b2
6.0.0.0b3
6.0.0.0rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
7.0.0
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
8.0.0
8.0.0.0b1
8.0.0.0b2
8.0.0.0rc1
8.0.0.0rc2
8.1.0
9.0.0
9.0.0.0b1
9.0.0.0rc1
9.0.0.0rc2
9.0.1
9.1.0
Fixed in
10.0.0
References
Updated Sep 25, 2024 · Source: OSV.dev |
9.1.0
minor
Dependencies (63)
+ 55 more |
|
10.0.0.0b3
pre
1 CVE
CVE-2018-16848
GHSA-443j-6p7g-6v4w
PYSEC-2020-240
May 24, 2022
OpenStack Mistral DoS
High
Network
Low
Low
None
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service. Affected versions
0
0.0.1
0.0.2
0.0.3
0.0.4
0.1
0.1.1
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
+ 71 more Show less
1.0.0.0rc2
1.0.1
10.0.0.0b1
10.0.0.0b2
10.0.0.0b3
10.0.0.0rc1
2.0.0
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2.0.0.0rc2
2.0.0.0rc3
3.0.0.0b1
3.0.2
4.0.0
4.0.0.0b1
4.0.0.0b2
4.0.0.0b3
4.0.0.0rc1
4.0.0.0rc2
4.0.1
4.0.2
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.0.0b1
6.0.0.0b2
6.0.0.0b3
6.0.0.0rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
7.0.0
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
8.0.0
8.0.0.0b1
8.0.0.0b2
8.0.0.0rc1
8.0.0.0rc2
8.1.0
9.0.0
9.0.0.0b1
9.0.0.0rc1
9.0.0.0rc2
9.0.1
9.1.0
Fixed in
10.0.0
References
Updated Sep 25, 2024 · Source: OSV.dev |
10.0.0.0b3
pre
Dependencies (39)
+ 31 more |
|
10.0.0.0b2
pre
1 CVE
CVE-2018-16848
GHSA-443j-6p7g-6v4w
PYSEC-2020-240
May 24, 2022
OpenStack Mistral DoS
High
Network
Low
Low
None
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service. Affected versions
0
0.0.1
0.0.2
0.0.3
0.0.4
0.1
0.1.1
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
+ 71 more Show less
1.0.0.0rc2
1.0.1
10.0.0.0b1
10.0.0.0b2
10.0.0.0b3
10.0.0.0rc1
2.0.0
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2.0.0.0rc2
2.0.0.0rc3
3.0.0.0b1
3.0.2
4.0.0
4.0.0.0b1
4.0.0.0b2
4.0.0.0b3
4.0.0.0rc1
4.0.0.0rc2
4.0.1
4.0.2
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.0.0b1
6.0.0.0b2
6.0.0.0b3
6.0.0.0rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
7.0.0
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
8.0.0
8.0.0.0b1
8.0.0.0b2
8.0.0.0rc1
8.0.0.0rc2
8.1.0
9.0.0
9.0.0.0b1
9.0.0.0rc1
9.0.0.0rc2
9.0.1
9.1.0
Fixed in
10.0.0
References
Updated Sep 25, 2024 · Source: OSV.dev |
10.0.0.0b2
pre
Dependencies (63)
+ 55 more |
|
10.0.0.0b1
pre
1 CVE
CVE-2018-16848
GHSA-443j-6p7g-6v4w
PYSEC-2020-240
May 24, 2022
OpenStack Mistral DoS
High
Network
Low
Low
None
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service. Affected versions
0
0.0.1
0.0.2
0.0.3
0.0.4
0.1
0.1.1
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
+ 71 more Show less
1.0.0.0rc2
1.0.1
10.0.0.0b1
10.0.0.0b2
10.0.0.0b3
10.0.0.0rc1
2.0.0
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2.0.0.0rc2
2.0.0.0rc3
3.0.0.0b1
3.0.2
4.0.0
4.0.0.0b1
4.0.0.0b2
4.0.0.0b3
4.0.0.0rc1
4.0.0.0rc2
4.0.1
4.0.2
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.0.0b1
6.0.0.0b2
6.0.0.0b3
6.0.0.0rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
7.0.0
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
8.0.0
8.0.0.0b1
8.0.0.0b2
8.0.0.0rc1
8.0.0.0rc2
8.1.0
9.0.0
9.0.0.0b1
9.0.0.0rc1
9.0.0.0rc2
9.0.1
9.1.0
Fixed in
10.0.0
References
Updated Sep 25, 2024 · Source: OSV.dev |
10.0.0.0b1
pre
Dependencies (63)
+ 55 more |
|
7.1.0
minor
1 CVE
CVE-2018-16848
GHSA-443j-6p7g-6v4w
PYSEC-2020-240
May 24, 2022
OpenStack Mistral DoS
High
Network
Low
Low
None
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service. Affected versions
0
0.0.1
0.0.2
0.0.3
0.0.4
0.1
0.1.1
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
+ 71 more Show less
1.0.0.0rc2
1.0.1
10.0.0.0b1
10.0.0.0b2
10.0.0.0b3
10.0.0.0rc1
2.0.0
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2.0.0.0rc2
2.0.0.0rc3
3.0.0.0b1
3.0.2
4.0.0
4.0.0.0b1
4.0.0.0b2
4.0.0.0b3
4.0.0.0rc1
4.0.0.0rc2
4.0.1
4.0.2
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.0.0b1
6.0.0.0b2
6.0.0.0b3
6.0.0.0rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
7.0.0
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
8.0.0
8.0.0.0b1
8.0.0.0b2
8.0.0.0rc1
8.0.0.0rc2
8.1.0
9.0.0
9.0.0.0b1
9.0.0.0rc1
9.0.0.0rc2
9.0.1
9.1.0
Fixed in
10.0.0
References
Updated Sep 25, 2024 · Source: OSV.dev |
7.1.0
minor
Dependencies (62)
+ 54 more |
|
8.1.0
minor
1 CVE
CVE-2018-16848
GHSA-443j-6p7g-6v4w
PYSEC-2020-240
May 24, 2022
OpenStack Mistral DoS
High
Network
Low
Low
None
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service. Affected versions
0
0.0.1
0.0.2
0.0.3
0.0.4
0.1
0.1.1
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
+ 71 more Show less
1.0.0.0rc2
1.0.1
10.0.0.0b1
10.0.0.0b2
10.0.0.0b3
10.0.0.0rc1
2.0.0
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2.0.0.0rc2
2.0.0.0rc3
3.0.0.0b1
3.0.2
4.0.0
4.0.0.0b1
4.0.0.0b2
4.0.0.0b3
4.0.0.0rc1
4.0.0.0rc2
4.0.1
4.0.2
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.0.0b1
6.0.0.0b2
6.0.0.0b3
6.0.0.0rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
7.0.0
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
8.0.0
8.0.0.0b1
8.0.0.0b2
8.0.0.0rc1
8.0.0.0rc2
8.1.0
9.0.0
9.0.0.0b1
9.0.0.0rc1
9.0.0.0rc2
9.0.1
9.1.0
Fixed in
10.0.0
References
Updated Sep 25, 2024 · Source: OSV.dev |
8.1.0
minor
Dependencies (63)
+ 55 more |
|
9.0.1
patch
1 CVE
CVE-2018-16848
GHSA-443j-6p7g-6v4w
PYSEC-2020-240
May 24, 2022
OpenStack Mistral DoS
High
Network
Low
Low
None
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service. Affected versions
0
0.0.1
0.0.2
0.0.3
0.0.4
0.1
0.1.1
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
+ 71 more Show less
1.0.0.0rc2
1.0.1
10.0.0.0b1
10.0.0.0b2
10.0.0.0b3
10.0.0.0rc1
2.0.0
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2.0.0.0rc2
2.0.0.0rc3
3.0.0.0b1
3.0.2
4.0.0
4.0.0.0b1
4.0.0.0b2
4.0.0.0b3
4.0.0.0rc1
4.0.0.0rc2
4.0.1
4.0.2
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.0.0b1
6.0.0.0b2
6.0.0.0b3
6.0.0.0rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
7.0.0
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
8.0.0
8.0.0.0b1
8.0.0.0b2
8.0.0.0rc1
8.0.0.0rc2
8.1.0
9.0.0
9.0.0.0b1
9.0.0.0rc1
9.0.0.0rc2
9.0.1
9.1.0
Fixed in
10.0.0
References
Updated Sep 25, 2024 · Source: OSV.dev |
9.0.1
patch
Dependencies (63)
+ 55 more |
|
9.0.0
major
1 CVE
CVE-2018-16848
GHSA-443j-6p7g-6v4w
PYSEC-2020-240
May 24, 2022
OpenStack Mistral DoS
High
Network
Low
Low
None
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service. Affected versions
0
0.0.1
0.0.2
0.0.3
0.0.4
0.1
0.1.1
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
+ 71 more Show less
1.0.0.0rc2
1.0.1
10.0.0.0b1
10.0.0.0b2
10.0.0.0b3
10.0.0.0rc1
2.0.0
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2.0.0.0rc2
2.0.0.0rc3
3.0.0.0b1
3.0.2
4.0.0
4.0.0.0b1
4.0.0.0b2
4.0.0.0b3
4.0.0.0rc1
4.0.0.0rc2
4.0.1
4.0.2
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.0.0b1
6.0.0.0b2
6.0.0.0b3
6.0.0.0rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
7.0.0
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
8.0.0
8.0.0.0b1
8.0.0.0b2
8.0.0.0rc1
8.0.0.0rc2
8.1.0
9.0.0
9.0.0.0b1
9.0.0.0rc1
9.0.0.0rc2
9.0.1
9.1.0
Fixed in
10.0.0
References
Updated Sep 25, 2024 · Source: OSV.dev |
9.0.0
major
Dependencies (63)
+ 55 more |
|
9.0.0.0rc2
pre
1 CVE
CVE-2018-16848
GHSA-443j-6p7g-6v4w
PYSEC-2020-240
May 24, 2022
OpenStack Mistral DoS
High
Network
Low
Low
None
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service. Affected versions
0
0.0.1
0.0.2
0.0.3
0.0.4
0.1
0.1.1
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
+ 71 more Show less
1.0.0.0rc2
1.0.1
10.0.0.0b1
10.0.0.0b2
10.0.0.0b3
10.0.0.0rc1
2.0.0
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2.0.0.0rc2
2.0.0.0rc3
3.0.0.0b1
3.0.2
4.0.0
4.0.0.0b1
4.0.0.0b2
4.0.0.0b3
4.0.0.0rc1
4.0.0.0rc2
4.0.1
4.0.2
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.0.0b1
6.0.0.0b2
6.0.0.0b3
6.0.0.0rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
7.0.0
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
8.0.0
8.0.0.0b1
8.0.0.0b2
8.0.0.0rc1
8.0.0.0rc2
8.1.0
9.0.0
9.0.0.0b1
9.0.0.0rc1
9.0.0.0rc2
9.0.1
9.1.0
Fixed in
10.0.0
References
Updated Sep 25, 2024 · Source: OSV.dev |
9.0.0.0rc2
pre
Dependencies (63)
+ 55 more |
|
9.0.0.0rc1
pre
1 CVE
CVE-2018-16848
GHSA-443j-6p7g-6v4w
PYSEC-2020-240
May 24, 2022
OpenStack Mistral DoS
High
Network
Low
Low
None
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service. Affected versions
0
0.0.1
0.0.2
0.0.3
0.0.4
0.1
0.1.1
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
+ 71 more Show less
1.0.0.0rc2
1.0.1
10.0.0.0b1
10.0.0.0b2
10.0.0.0b3
10.0.0.0rc1
2.0.0
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2.0.0.0rc2
2.0.0.0rc3
3.0.0.0b1
3.0.2
4.0.0
4.0.0.0b1
4.0.0.0b2
4.0.0.0b3
4.0.0.0rc1
4.0.0.0rc2
4.0.1
4.0.2
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.0.0b1
6.0.0.0b2
6.0.0.0b3
6.0.0.0rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
7.0.0
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
8.0.0
8.0.0.0b1
8.0.0.0b2
8.0.0.0rc1
8.0.0.0rc2
8.1.0
9.0.0
9.0.0.0b1
9.0.0.0rc1
9.0.0.0rc2
9.0.1
9.1.0
Fixed in
10.0.0
References
Updated Sep 25, 2024 · Source: OSV.dev |
9.0.0.0rc1
pre
Dependencies (62)
+ 54 more |
|
9.0.0.0b1
pre
1 CVE
CVE-2018-16848
GHSA-443j-6p7g-6v4w
PYSEC-2020-240
May 24, 2022
OpenStack Mistral DoS
High
Network
Low
Low
None
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service. Affected versions
0
0.0.1
0.0.2
0.0.3
0.0.4
0.1
0.1.1
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
+ 71 more Show less
1.0.0.0rc2
1.0.1
10.0.0.0b1
10.0.0.0b2
10.0.0.0b3
10.0.0.0rc1
2.0.0
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2.0.0.0rc2
2.0.0.0rc3
3.0.0.0b1
3.0.2
4.0.0
4.0.0.0b1
4.0.0.0b2
4.0.0.0b3
4.0.0.0rc1
4.0.0.0rc2
4.0.1
4.0.2
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.0.0b1
6.0.0.0b2
6.0.0.0b3
6.0.0.0rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
7.0.0
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
8.0.0
8.0.0.0b1
8.0.0.0b2
8.0.0.0rc1
8.0.0.0rc2
8.1.0
9.0.0
9.0.0.0b1
9.0.0.0rc1
9.0.0.0rc2
9.0.1
9.1.0
Fixed in
10.0.0
References
Updated Sep 25, 2024 · Source: OSV.dev |
9.0.0.0b1
pre
Dependencies (62)
+ 54 more |
|
5.2.8
patch
2 CVEs
CVE-2018-16848
GHSA-443j-6p7g-6v4w
PYSEC-2020-240
May 24, 2022
OpenStack Mistral DoS
High
Network
Low
Low
None
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service. Affected versions
0
0.0.1
0.0.2
0.0.3
0.0.4
0.1
0.1.1
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
+ 71 more Show less
1.0.0.0rc2
1.0.1
10.0.0.0b1
10.0.0.0b2
10.0.0.0b3
10.0.0.0rc1
2.0.0
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2.0.0.0rc2
2.0.0.0rc3
3.0.0.0b1
3.0.2
4.0.0
4.0.0.0b1
4.0.0.0b2
4.0.0.0b3
4.0.0.0rc1
4.0.0.0rc2
4.0.1
4.0.2
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.0.0b1
6.0.0.0b2
6.0.0.0b3
6.0.0.0rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
7.0.0
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
8.0.0
8.0.0.0b1
8.0.0.0b2
8.0.0.0rc1
8.0.0.0rc2
8.1.0
9.0.0
9.0.0.0b1
9.0.0.0rc1
9.0.0.0rc2
9.0.1
9.1.0
Fixed in
10.0.0
References
Updated Sep 25, 2024 · Source: OSV.dev
CVE-2018-16849
GHSA-fqw7-c6vr-q29m
PYSEC-2018-92
May 13, 2022
openstack-mistral Discloses the presence of arbitrary files within the filesystem
High
Network
Low
None
None
A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor's filesystem. Affected versions
0
0.0.1
0.0.2
0.0.3
0.0.4
0.1
0.1.1
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
+ 50 more Show less
1.0.0.0rc2
1.0.1
2.0.0
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2.0.0.0rc2
2.0.0.0rc3
3.0.0.0b1
3.0.2
4.0.0
4.0.0.0b1
4.0.0.0b2
4.0.0.0b3
4.0.0.0rc1
4.0.0.0rc2
4.0.1
4.0.2
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.0.0b1
6.0.0.0b2
6.0.0.0b3
6.0.0.0rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
7.0.0
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
Fixed in
7.0.1
References
Updated Sep 24, 2024 · Source: OSV.dev |
5.2.8
patch
Dependencies (60)
+ 52 more |
|
8.0.0
major
1 CVE
CVE-2018-16848
GHSA-443j-6p7g-6v4w
PYSEC-2020-240
May 24, 2022
OpenStack Mistral DoS
High
Network
Low
Low
None
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service. Affected versions
0
0.0.1
0.0.2
0.0.3
0.0.4
0.1
0.1.1
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
+ 71 more Show less
1.0.0.0rc2
1.0.1
10.0.0.0b1
10.0.0.0b2
10.0.0.0b3
10.0.0.0rc1
2.0.0
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2.0.0.0rc2
2.0.0.0rc3
3.0.0.0b1
3.0.2
4.0.0
4.0.0.0b1
4.0.0.0b2
4.0.0.0b3
4.0.0.0rc1
4.0.0.0rc2
4.0.1
4.0.2
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.0.0b1
6.0.0.0b2
6.0.0.0b3
6.0.0.0rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
7.0.0
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
8.0.0
8.0.0.0b1
8.0.0.0b2
8.0.0.0rc1
8.0.0.0rc2
8.1.0
9.0.0
9.0.0.0b1
9.0.0.0rc1
9.0.0.0rc2
9.0.1
9.1.0
Fixed in
10.0.0
References
Updated Sep 25, 2024 · Source: OSV.dev |
8.0.0
major
Dependencies (63)
+ 55 more |
|
8.0.0.0rc2
pre
1 CVE
CVE-2018-16848
GHSA-443j-6p7g-6v4w
PYSEC-2020-240
May 24, 2022
OpenStack Mistral DoS
High
Network
Low
Low
None
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service. Affected versions
0
0.0.1
0.0.2
0.0.3
0.0.4
0.1
0.1.1
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
+ 71 more Show less
1.0.0.0rc2
1.0.1
10.0.0.0b1
10.0.0.0b2
10.0.0.0b3
10.0.0.0rc1
2.0.0
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2.0.0.0rc2
2.0.0.0rc3
3.0.0.0b1
3.0.2
4.0.0
4.0.0.0b1
4.0.0.0b2
4.0.0.0b3
4.0.0.0rc1
4.0.0.0rc2
4.0.1
4.0.2
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.0.0b1
6.0.0.0b2
6.0.0.0b3
6.0.0.0rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
7.0.0
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
8.0.0
8.0.0.0b1
8.0.0.0b2
8.0.0.0rc1
8.0.0.0rc2
8.1.0
9.0.0
9.0.0.0b1
9.0.0.0rc1
9.0.0.0rc2
9.0.1
9.1.0
Fixed in
10.0.0
References
Updated Sep 25, 2024 · Source: OSV.dev |
8.0.0.0rc2
pre
Dependencies (63)
+ 55 more |
|
8.0.0.0rc1
pre
1 CVE
CVE-2018-16848
GHSA-443j-6p7g-6v4w
PYSEC-2020-240
May 24, 2022
OpenStack Mistral DoS
High
Network
Low
Low
None
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service. Affected versions
0
0.0.1
0.0.2
0.0.3
0.0.4
0.1
0.1.1
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
+ 71 more Show less
1.0.0.0rc2
1.0.1
10.0.0.0b1
10.0.0.0b2
10.0.0.0b3
10.0.0.0rc1
2.0.0
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2.0.0.0rc2
2.0.0.0rc3
3.0.0.0b1
3.0.2
4.0.0
4.0.0.0b1
4.0.0.0b2
4.0.0.0b3
4.0.0.0rc1
4.0.0.0rc2
4.0.1
4.0.2
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.0.0b1
6.0.0.0b2
6.0.0.0b3
6.0.0.0rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
7.0.0
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
8.0.0
8.0.0.0b1
8.0.0.0b2
8.0.0.0rc1
8.0.0.0rc2
8.1.0
9.0.0
9.0.0.0b1
9.0.0.0rc1
9.0.0.0rc2
9.0.1
9.1.0
Fixed in
10.0.0
References
Updated Sep 25, 2024 · Source: OSV.dev |
8.0.0.0rc1
pre
Dependencies (63)
+ 55 more |
|
8.0.0.0b2
pre
1 CVE
CVE-2018-16848
GHSA-443j-6p7g-6v4w
PYSEC-2020-240
May 24, 2022
OpenStack Mistral DoS
High
Network
Low
Low
None
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service. Affected versions
0
0.0.1
0.0.2
0.0.3
0.0.4
0.1
0.1.1
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
+ 71 more Show less
1.0.0.0rc2
1.0.1
10.0.0.0b1
10.0.0.0b2
10.0.0.0b3
10.0.0.0rc1
2.0.0
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2.0.0.0rc2
2.0.0.0rc3
3.0.0.0b1
3.0.2
4.0.0
4.0.0.0b1
4.0.0.0b2
4.0.0.0b3
4.0.0.0rc1
4.0.0.0rc2
4.0.1
4.0.2
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.0.0b1
6.0.0.0b2
6.0.0.0b3
6.0.0.0rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
7.0.0
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
7.0.1
7.0.2
7.0.3
7.0.4
7.1.0
8.0.0
8.0.0.0b1
8.0.0.0b2
8.0.0.0rc1
8.0.0.0rc2
8.1.0
9.0.0
9.0.0.0b1
9.0.0.0rc1
9.0.0.0rc2
9.0.1
9.1.0
Fixed in
10.0.0
References
Updated Sep 25, 2024 · Source: OSV.dev |
8.0.0.0b2
pre
Dependencies (63)
+ 55 more |