CVE-2026-94571
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encodes control characters before validating, and thus newlines passed structural checks, but Octavia stored and wrote the raw unencoded value directly into the HAProxy configuration generated on the amphora. An authenticated project member who owns a load balancer can therefore inject arbitrary HAProxy directives through a REDIRECT_TO_URL L7 policy. Only deployments using the Amphora provider are affected.
| CWE | CWE-94 |
| Vendor | openstack |
| Product | octavia |
| Published | Sep 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for openstack octavia
Be the first to know when new unknown vulnerabilities affecting openstack octavia are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
OpenStack / Octavia
0.8.0 < 16.1.0 17.0.0 < 17.0.1 18.0.0 < 18.0.1
References
bugs.launchpad.net: https://bugs.launchpad.net/octavia/+bug/2162103 bugs.launchpad.net: https://bugs.launchpad.net/octavia/+bug/2167565 bugs.debian.org: https://bugs.debian.org/1148175 opendev.org: https://opendev.org/openstack/octavia/commit/bad7074621562d90a38be4639c1ab3e245f5bf39 security.openstack.org: https://security.openstack.org/ossa/OSSA-2026-039.html openwall.com: https://openwall.com/lists/oss-security/2026/09/21/6