CVE Tools

Openstack

241 CVEs tracked since 2011. Since Dec 2011, none of them reached CISA KEV.

Openstack CVEs per month

Dec 2011 to Aug 2026. Point at a month, or focus the strip and use the arrow keys.
Openstack CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2011-1210
2012-0110
2012-02null or fewer
2012-03null or fewer
2012-04null or fewer
2012-05null or fewer
2012-0640
2012-0740
2012-0820
2012-0930
2012-1030
2012-1120
2012-1240
2013-01null or fewer
2013-0230
2013-0360
2013-0440
2013-0530
2013-06null or fewer
2013-0710
2013-0840
2013-0970
2013-1040
2013-1160
2013-1240
2014-0140
2014-0250
2014-0320
2014-0470
2014-0540
2014-0630
2014-0730
2014-0870
2014-09null or fewer
2014-10170
2014-1120
2014-12null or fewer
2015-0140
2015-0220
2015-03null or fewer
2015-0430
2015-0520
2015-0610
2015-07null or fewer
2015-0840
2015-0910
2015-1060
2015-1110
2015-12null or fewer
2016-0160
2016-0210
2016-03null or fewer
2016-0440
2016-05null or fewer
2016-0630
2016-0710
2016-08null or fewer
2016-0920
2016-1010
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-0330
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-0840
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-1220
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-0750
2018-0820
2018-0920
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-1140
2019-1260
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-0830
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-0840
2022-0930
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-0130
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05140
2026-06100
2026-07null or fewer
2026-08140

Products

The products that kept showing up in Openstack's monthly top three, with their CVEs summed over those months.

  1. Keystone3419 months
  2. Nova2618 months
  3. Folsom2412 months
  4. Horizon1610 months
  5. Neutron1510 months
  6. Essex147 months
  7. Grizzly127 months
  8. Image Registry and Delivery Service \(Glance\)127 months
  9. Ironic103 months
  10. Swift107 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Openstack.

  1. CVE-2026-97404In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticated remote attacker who knows a target ...—
  2. CVE-2026-97149In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, and path, and thus the list of d...—
  3. CVE-2026-94572In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy confi...—
  4. CVE-2026-94571In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encode...—
  5. CVE-2026-93854In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The...—
  6. CVE-2026-93852In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authentica...—
  7. CVE-2026-71198In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks t...—
  8. CVE-2026-90461OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.6.3
  9. CVE-2026-90460An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are no...—
  10. CVE-2026-80183In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project...—
  11. CVE-2026-80184In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) could be submitted to the token-method authentic...—
  12. CVE-2026-80182In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegat...—
  13. CVE-2026-77648In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF...2.2
  14. CVE-2026-76878In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather th...—
  15. CVE-2026-74250In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.6.3

The record

Peak rank
#16 in Sep 2013
Busiest month shown
Oct 2014, 17 CVEs
Months with a KEV entry
0 since Dec 2011
Monthly snapshots
60 since 2011
Openstack's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store