๐Ÿ” CVE Alert

CVE-2026-71191

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.

CWE CWE-863
Vendor openstack
Product swift
Published Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for openstack swift

Be the first to know when new unknown vulnerabilities affecting openstack swift are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OpenStack / Swift
2.18.0 < 2.35.4 2.36.0 < 2.36.3 2.37.0 < 2.37.3 2.38.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
launchpad.net: https://launchpad.net/bugs/2158733 openwall.com: https://openwall.com/lists/oss-security/2026/07/28/26 security.openstack.org: https://security.openstack.org/ossa/OSSA-2026-030.html