PT-2026-96245 · Openstack · Openstack Octavia

CVE-2026-94571

·

Published

2026-09-21

·

Updated

2026-09-24

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions OpenStack Octavia versions prior to 18.0.1
Description The Amphora provider driver fails to reject control characters within the redirect url and redirect prefix fields of the L7 policy. While the RFC 3986 URL validator percent-encodes these characters during validation, allowing newlines to pass structural checks, the system stores and writes the raw unencoded values directly into the HAProxy configuration on the amphora. This allows an authenticated project member who owns a load balancer to inject arbitrary HAProxy directives via a REDIRECT TO URL L7 policy.
Recommendations Update to version 18.0.1 or later.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94571
USN-8814-1

Affected Products

Openstack Octavia