PT-2026-96246 · Haproxy+1 · Haproxy+1
CVE-2026-94572
·
Published
2026-09-21
·
Updated
2026-09-24
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
OpenStack Octavia versions prior to 18.0.1
Description
The Amphora provider driver fails to validate the
tls ciphers field for listeners and pools against control characters. Because this value is written directly into the HAProxy configuration on the amphora, an authenticated project member with ownership of a TLS-enabled load balancer can inject a newline character to insert arbitrary HAProxy configuration directives.Recommendations
Update to version 18.0.1 or later.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Haproxy
Openstack Octavia