PT-2026-97695 · Openstack · Openstack Swift
CVE-2026-97149
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
OpenStack Swift versions prior to 2.38.2
Description
The tempurl middleware fails to reject the
X-Copy-From header during PUT requests. Because a TempURL signature only validates the method, expiry, and path, the system relies on a list of disallowed headers to prevent unauthorized modifications to the request. An attacker with a PUT TempURL for a specific object can include the X-Copy-From header to specify any other object within the same account. The copy middleware then copies the target object to the destination, allowing the attacker to retrieve the victim's data using a GET TempURL for that destination object. This issue only affects deployments using the default proxy pipeline containing both tempurl and copy middleware with account-level TempURL keys. Copies across different account boundaries are not possible.Recommendations
Update OpenStack Swift to version 2.38.2 or later.
Fix
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Swift