neutron
OpenStack Networking
Activity
- Latest release
- 4d ago
- Total releases
- 187
- Cadence
- ~13 days
- Last 12 months
- 23
Details
- License
- Apache-2.0
- First release
- Jan 24, 2018
| Version | Released | |
|---|---|---|
27.0.4
patch
2 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev |
27.0.4
patch
Dependencies (53)
+ 45 more |
|
26.0.6
patch
2 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev |
26.0.6
patch
Dependencies (53)
+ 45 more |
|
28.0.2
patch
1 CVE
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev |
28.0.2
patch
Dependencies (53)
+ 45 more |
|
29.0.0.0rc1
pre
1 CVE
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev |
29.0.0.0rc1
pre
Dependencies (52)
+ 44 more |
|
26.0.5
patch
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
26.0.5
patch
Dependencies (53)
+ 45 more |
|
29.0.0.0b1
pre
2 CVEs
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
29.0.0.0b1
pre
Dependencies (52)
+ 44 more |
|
26.0.4
patch
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
26.0.4
patch
Dependencies (53)
+ 45 more |
|
27.0.3
patch
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
27.0.3
patch
Dependencies (53)
+ 45 more |
|
28.0.1
patch
2 CVEs
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
28.0.1
patch
Dependencies (53)
+ 45 more |
|
26.0.3
patch
4 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49299
PYSEC-2026-2678
GHSA-xv24-hxh9-2hh9
Jul 13, 2026
OpenStack Neutron has an Incorrect Authorization issue
Medium
Network
Low
Low
None
In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected. Affected versions
26.0.0
26.0.1
26.0.2
26.0.3
27.0.0
27.0.1
27.0.2
28.0.0
Fixed in
26.0.4
27.0.3
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
26.0.3
patch
Dependencies (53)
+ 45 more |
|
27.0.2
patch
4 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49299
PYSEC-2026-2678
GHSA-xv24-hxh9-2hh9
Jul 13, 2026
OpenStack Neutron has an Incorrect Authorization issue
Medium
Network
Low
Low
None
In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected. Affected versions
26.0.0
26.0.1
26.0.2
26.0.3
27.0.0
27.0.1
27.0.2
28.0.0
Fixed in
26.0.4
27.0.3
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
27.0.2
patch
Dependencies (53)
+ 45 more |
|
25.2.3
patch
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
25.2.3
patch
Dependencies (54)
+ 46 more |
|
28.0.0
major
4 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49299
PYSEC-2026-2678
GHSA-xv24-hxh9-2hh9
Jul 13, 2026
OpenStack Neutron has an Incorrect Authorization issue
Medium
Network
Low
Low
None
In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected. Affected versions
26.0.0
26.0.1
26.0.2
26.0.3
27.0.0
27.0.1
27.0.2
28.0.0
Fixed in
26.0.4
27.0.3
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
28.0.0
major
Dependencies (53)
+ 45 more |
|
28.0.0.0rc2
pre
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
28.0.0.0rc2
pre
Dependencies (53)
+ 45 more |
|
28.0.0.0rc1
pre
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
28.0.0.0rc1
pre
Dependencies (53)
+ 45 more |
|
25.2.2
patch
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
25.2.2
patch
Dependencies (53)
+ 45 more |
|
28.0.0.0b2
pre
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
28.0.0.0b2
pre
Dependencies (53)
+ 45 more |
|
28.0.0.0b1
pre
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
28.0.0.0b1
pre
Dependencies (53)
+ 45 more |
|
26.0.2
patch
4 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49299
PYSEC-2026-2678
GHSA-xv24-hxh9-2hh9
Jul 13, 2026
OpenStack Neutron has an Incorrect Authorization issue
Medium
Network
Low
Low
None
In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected. Affected versions
26.0.0
26.0.1
26.0.2
26.0.3
27.0.0
27.0.1
27.0.2
28.0.0
Fixed in
26.0.4
27.0.3
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
26.0.2
patch
Dependencies (53)
+ 45 more |
|
27.0.1
patch
4 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49299
PYSEC-2026-2678
GHSA-xv24-hxh9-2hh9
Jul 13, 2026
OpenStack Neutron has an Incorrect Authorization issue
Medium
Network
Low
Low
None
In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected. Affected versions
26.0.0
26.0.1
26.0.2
26.0.3
27.0.0
27.0.1
27.0.2
28.0.0
Fixed in
26.0.4
27.0.3
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
27.0.1
patch
Dependencies (53)
+ 45 more |
|
25.2.1
patch
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
25.2.1
patch
Dependencies (53)
+ 45 more |
|
24.2.2
patch
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
24.2.2
patch
Dependencies (55)
+ 47 more |
|
27.0.0
major
4 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49299
PYSEC-2026-2678
GHSA-xv24-hxh9-2hh9
Jul 13, 2026
OpenStack Neutron has an Incorrect Authorization issue
Medium
Network
Low
Low
None
In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected. Affected versions
26.0.0
26.0.1
26.0.2
26.0.3
27.0.0
27.0.1
27.0.2
28.0.0
Fixed in
26.0.4
27.0.3
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
27.0.0
major
Dependencies (53)
+ 45 more |
|
27.0.0.0rc1
pre
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
27.0.0.0rc1
pre
Dependencies (53)
+ 45 more |
|
24.2.1
patch
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
24.2.1
patch
Dependencies (55)
+ 47 more |
|
27.0.0.0b1
pre
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
27.0.0.0b1
pre
Dependencies (53)
+ 45 more |
|
26.0.1
patch
4 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49299
PYSEC-2026-2678
GHSA-xv24-hxh9-2hh9
Jul 13, 2026
OpenStack Neutron has an Incorrect Authorization issue
Medium
Network
Low
Low
None
In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected. Affected versions
26.0.0
26.0.1
26.0.2
26.0.3
27.0.0
27.0.1
27.0.2
28.0.0
Fixed in
26.0.4
27.0.3
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
26.0.1
patch
Dependencies (53)
+ 45 more |
|
24.2.0
minor
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
24.2.0
minor
Dependencies (55)
+ 47 more |
|
25.2.0
minor
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
25.2.0
minor
Dependencies (53)
+ 45 more |
|
23.5.0
minor
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
23.5.0
minor
Dependencies (56)
+ 48 more |
|
26.0.0
major
4 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49299
PYSEC-2026-2678
GHSA-xv24-hxh9-2hh9
Jul 13, 2026
OpenStack Neutron has an Incorrect Authorization issue
Medium
Network
Low
Low
None
In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected. Affected versions
26.0.0
26.0.1
26.0.2
26.0.3
27.0.0
27.0.1
27.0.2
28.0.0
Fixed in
26.0.4
27.0.3
28.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
26.0.0
major
Dependencies (53)
+ 45 more |
|
26.0.0.0rc2
pre
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
26.0.0.0rc2
pre
Dependencies (53)
+ 45 more |
|
26.0.0.0rc1
pre
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
26.0.0.0rc1
pre
Dependencies (53)
+ 45 more |
|
23.4.0
minor
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
23.4.0
minor
Dependencies (56)
+ 48 more |
|
25.1.0
minor
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
25.1.0
minor
Dependencies (53)
+ 45 more |
|
24.1.0
minor
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
24.1.0
minor
Dependencies (55)
+ 47 more |
|
23.3.0
minor
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
23.3.0
minor
Dependencies (56)
+ 48 more |
|
26.0.0.0b2
pre
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
26.0.0.0b2
pre
Dependencies (53)
+ 45 more |
|
26.0.0.0b1
pre
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
26.0.0.0b1
pre
Dependencies (53)
+ 45 more |
|
25.0.0
major
4 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2024-53916
PYSEC-2026-1693
GHSA-f27h-g923-68hw
Jul 07, 2026
OpenStack Neutron can use an incorrect ID during policy enforcement
Medium
Network
Low
None
None
In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on network objects that do not belong to the tenant, and this action is not subjected to the proper policy authorization check. This affects 23 before 23.2.1, 24 before 24.0.2, and 25 before 25.0.1. Affected versions
23.0.0
23.1.0
23.2.0
24.0.0
24.0.1
25.0.0
Fixed in
23.2.1
24.0.2
25.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
25.0.0
major
Dependencies (53)
+ 45 more |
|
25.0.0.0rc2
pre
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
25.0.0.0rc2
pre
Dependencies (53)
+ 45 more |
|
25.0.0.0rc1
pre
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
25.0.0.0rc1
pre
Dependencies (53)
+ 45 more |
|
22.2.1
patch
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
22.2.1
patch
Dependencies (56)
+ 48 more |
|
24.0.1
patch
4 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2024-53916
PYSEC-2026-1693
GHSA-f27h-g923-68hw
Jul 07, 2026
OpenStack Neutron can use an incorrect ID during policy enforcement
Medium
Network
Low
None
None
In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on network objects that do not belong to the tenant, and this action is not subjected to the proper policy authorization check. This affects 23 before 23.2.1, 24 before 24.0.2, and 25 before 25.0.1. Affected versions
23.0.0
23.1.0
23.2.0
24.0.0
24.0.1
25.0.0
Fixed in
23.2.1
24.0.2
25.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
24.0.1
patch
Dependencies (55)
+ 47 more |
|
23.2.0
minor
4 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2024-53916
PYSEC-2026-1693
GHSA-f27h-g923-68hw
Jul 07, 2026
OpenStack Neutron can use an incorrect ID during policy enforcement
Medium
Network
Low
None
None
In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on network objects that do not belong to the tenant, and this action is not subjected to the proper policy authorization check. This affects 23 before 23.2.1, 24 before 24.0.2, and 25 before 25.0.1. Affected versions
23.0.0
23.1.0
23.2.0
24.0.0
24.0.1
25.0.0
Fixed in
23.2.1
24.0.2
25.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
23.2.0
minor
Dependencies (56)
+ 48 more |
|
22.2.0
minor
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
22.2.0
minor
Dependencies (56)
+ 48 more |
|
25.0.0.0b1
pre
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
25.0.0.0b1
pre
Dependencies (55)
+ 47 more |
|
21.2.1
patch
4 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2023-3637
PYSEC-2026-1694
GHSA-r3jh-qhgj-gvr8
Jul 07, 2026
Denial of service in neutron
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 117 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
21.2.1
patch
Dependencies (56)
+ 48 more |
|
24.0.0
major
4 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2024-53916
PYSEC-2026-1693
GHSA-f27h-g923-68hw
Jul 07, 2026
OpenStack Neutron can use an incorrect ID during policy enforcement
Medium
Network
Low
None
None
In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on network objects that do not belong to the tenant, and this action is not subjected to the proper policy authorization check. This affects 23 before 23.2.1, 24 before 24.0.2, and 25 before 25.0.1. Affected versions
23.0.0
23.1.0
23.2.0
24.0.0
24.0.1
25.0.0
Fixed in
23.2.1
24.0.2
25.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
24.0.0
major
Dependencies (55)
+ 47 more |
|
24.0.0.0rc2
pre
3 CVEs
CVE-2026-50266
PYSEC-2026-3491
GHSA-qmc5-gv6v-8p22
Jul 23, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
2.2
/ 10
Low
Network
High
High
None
Unchanged
None
Low
None
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018). Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 170 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
Fixed in
28.0.1
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2015-3221
PYSEC-2026-856
GHSA-wf44-4mgj-rwvx
Jul 06, 2026
OpenStack Neutron Improper Input Validation vulnerability OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. Affected versions
0.0
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
+ 172 more Show less
12.0.0.0rc1
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
2014.2.4
2015.1.1
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2017-7543
PYSEC-2026-686
GHSA-hvxr-2fvv-c3wq
Jul 02, 2026
OpenStack Neutron Race Condition vulnerability
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources. Affected versions
10.0.5
10.0.6
10.0.7
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
12.0.0
12.0.0.0b3
12.0.0.0rc1
+ 171 more Show less
12.0.0.0rc2
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.1.1
13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0
14.2.0
14.3.0
14.3.1
14.4.0
14.4.1
14.4.2
15.0.0
15.0.0.0b1
15.0.0.0rc1
15.0.0.0rc2
15.0.1
15.0.2
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
16.0.0
16.0.0.0b1
16.0.0.0rc1
16.0.0.0rc2
16.1.0
16.2.0
16.3.0
16.3.1
16.3.2
16.4.0
16.4.1
16.4.2
17.0.0
17.0.0.0rc1
17.0.0.0rc2
17.1.0
17.1.1
17.1.2
17.2.0
17.2.1
17.3.0
17.4.0
17.4.1
18.0.0
18.0.0.0rc1
18.0.0.0rc2
18.1.0
18.1.1
18.2.0
18.3.0
18.4.0
18.5.0
18.6.0
19.0.0
19.0.0.0rc1
19.0.0.0rc2
19.1.0
19.2.0
19.3.0
19.4.0
19.5.0
19.6.0
19.7.0
20.0.0
20.0.0.0rc1
20.0.0.0rc2
20.1.0
20.2.0
20.3.0
20.3.1
20.4.0
20.5.0
21.0.0
21.0.0.0rc1
21.0.0.0rc2
21.1.0
21.1.1
21.1.2
21.2.0
21.2.1
22.0.0
22.0.0.0rc1
22.0.0.0rc2
22.0.1
22.0.2
22.1.0
22.2.0
22.2.1
23.0.0
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.1.0
23.2.0
23.3.0
23.4.0
23.5.0
24.0.0
24.0.0.0b1
24.0.0.0rc1
24.0.0.0rc2
24.0.1
24.1.0
24.2.0
24.2.1
24.2.2
25.0.0
25.0.0.0b1
25.0.0.0rc1
25.0.0.0rc2
25.1.0
25.2.0
25.2.1
25.2.2
25.2.3
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.0.0
27.0.0.0b1
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.0.0
28.0.0.0b1
28.0.0.0b2
28.0.0.0rc1
28.0.0.0rc2
28.0.1
29.0.0.0b1
Fixed in
7.2.0-12.1
8.3.0-11.1
9.3.1-2.1
10.0.2-1.1
References Updated Jul 21, 2026 · Source: OSV.dev |
24.0.0.0rc2
pre
Dependencies (55)
+ 47 more |