CVE-2026-94572
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the amphora, and thus an authenticated project member who owns a TLS-enabled load balancer can embed a newline and inject arbitrary HAProxy configuration directives. Only deployments using the Amphora provider are affected.
| CWE | CWE-94 |
| Vendor | openstack |
| Product | octavia |
| Published | Sep 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for openstack octavia
Be the first to know when new unknown vulnerabilities affecting openstack octavia are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
OpenStack / Octavia
6.0.0 < 16.1.0 17.0.0 < 17.0.1 18.0.0 < 18.0.1
References
bugs.launchpad.net: https://bugs.launchpad.net/octavia/+bug/2162101 bugs.launchpad.net: https://bugs.launchpad.net/octavia/+bug/2167565 bugs.debian.org: https://bugs.debian.org/1148175 opendev.org: https://opendev.org/openstack/octavia/commit/cad62902e4984a46ad80cbfa943e90006d8d599d security.openstack.org: https://security.openstack.org/ossa/OSSA-2026-039.html openwall.com: https://openwall.com/lists/oss-security/2026/09/21/6