๐Ÿ” CVE Alert

CVE-2026-71190

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The "qdtext" pattern (?:[^"]|\\.)* allows an unauthenticated remote attacker to send a crafted Accept header that causes exponential CPU consumption in the proxy worker. A payload of 32 backslash-character pairs exceeds 30 seconds of CPU time. No authentication is required. Repeated requests can exhaust all proxy worker threads, resulting in a complete denial of service.

CWE CWE-1333
Vendor openstack
Product swift
Published Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for openstack swift

Be the first to know when new unknown vulnerabilities affecting openstack swift are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OpenStack / Swift
1.9.1 < 2.35.4 2.36.0 < 2.36.3 2.37.0 < 2.37.3 2.38.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
launchpad.net: https://launchpad.net/bugs/2158771 openwall.com: https://openwall.com/lists/oss-security/2026/07/28/27 security.openstack.org: https://security.openstack.org/ossa/OSSA-2026-031.html