PT-2026-96245 · Openstack · Openstack Octavia
CVE-2026-94571
·
Published
2026-09-21
·
Updated
2026-09-24
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
OpenStack Octavia versions prior to 18.0.1
Description
The Amphora provider driver fails to reject control characters within the
redirect url and redirect prefix fields of the L7 policy. While the RFC 3986 URL validator percent-encodes these characters during validation, allowing newlines to pass structural checks, the system stores and writes the raw unencoded values directly into the HAProxy configuration on the amphora. This allows an authenticated project member who owns a load balancer to inject arbitrary HAProxy directives via a REDIRECT TO URL L7 policy.Recommendations
Update to version 18.0.1 or later.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Octavia