Openstack Platform
39 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Openstack Platform, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Openstack Platform CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 1 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 39 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High16
- Medium20
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Openstack Platform.
- CVE-2023-1932Hibernate-validator: rendering of invalid html with safehtml leads to html injection and xss6.1
- CVE-2024-8007Openstack-tripleo-common: rhosp director disables tls verification for registry mirrors8.1
- CVE-2024-7319Openstack-heat: incomplete fix for cve-2023-16255.0
- CVE-2023-6725Tripleo-ansible: bind keys are world readable5.5
- CVE-2023-48795The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (fr...5.9
- CVE-2023-5625Python-eventlet: patch regression for cve-2021-21419 in some red hat builds5.3
- CVE-2023-44487The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.7.5
- CVE-2023-1633Insecure barbican configuration file leaking credential6.6
- CVE-2023-1636Incomplete container isolation6.0
- CVE-2023-1625Information leak in api7.4
- CVE-2022-3596Instack-undercloud: rsync leaks information to undercloud7.5
- CVE-2022-3261Plain-text passwords saved in /var/log/messages4.4
- CVE-2023-1108Undertow: infinite loop in sslconduit during close7.5
- CVE-2023-3637Openstack-neutron: unrestricted creation of security groups (fix for cve-2022-3277)4.3
- CVE-2023-3354Improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of service7.5
Product grouping is registry-driven, with AI assist and human review. How it works