Search CVE reports


Toggle filters

1 – 6 of 6 results


CVE-2026-94572

Medium priority
Needs evaluation

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the...

1 affected package

octavia

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
octavia Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-94571

Medium priority
Needs evaluation

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encodes control characters before...

1 affected package

octavia

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
octavia Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-74248

Medium priority
Needs evaluation

OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All...

1 affected package

octavia

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
octavia Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2019-17134

Medium priority
Fixed

Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue...

1 affected package

octavia

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
octavia Not in release
Show less packages

CVE-2019-3895

Medium priority
Needs evaluation

An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant that a...

1 affected package

octavia

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
octavia Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2018-16856

Medium priority
Needs evaluation

In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive...

1 affected package

octavia

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
octavia Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages