Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2531▼ 362 respecto a la semana anterior
Críticas / altas1338▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
609 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.43% | — | Openstack NeutronAI | 5/8/2026 | 31/8/2026 | In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3 routing and address scope behavior for victim… | |
| Aplazada | Media (4.8) | 0.48% | — | Openstack ZaqarAI | 24/7/2026 | 30/7/2026 | OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known. | |
| Aplazada | Alta (7.2) | 0.78% | — | Openstack Ironic Python AgentAI | 24/7/2026 | 30/7/2026 | In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell. | |
| Pendiente de análisis | Media (5.5) | 0.15% | — | Openstack Ironic Python AgentAI | 24/7/2026 | 9/9/2026 | In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it. | |
| Aplazada | Alta (8.2) | 0.48% | — | Openstack IronicAI | 10/7/2026 | 10/7/2026 | In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control. | |
| Aplazada | Media (5.5) | 0.41% | — | Openstack IronicAI | 10/7/2026 | 10/7/2026 | OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization. | |
| Analizada | Media (5.3) | 0.22% | — | Openstack Swift | 23/6/2026 | 29/6/2026 | In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update… | |
| Analizada | Media (6.8) | 0.46% | — | Openstack Horizon | 17/6/2026 | 22/9/2026 | OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. | |
| Analizada | Alta (8.5) | 0.46% | — | Openstack Nova | 16/6/2026 | 26/6/2026 | In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation. | |
| Aplazada | Media (6.8) | 0.47% | — | Openstack IronicAI | 14/6/2026 | 23/7/2026 | In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. | |
| Modificada | Alta (7.5) | 0.74% | — | Openstack Ironic | 5/6/2026 | 23/7/2026 | In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash. | |
| Pendiente de análisis | Baja (2.2) | 0.38% | — | Openstack NeutronAI | 4/6/2026 | 22/7/2026 | In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network… | |
| Pendiente de análisis | Alta (7.4) | 0.28% | — | Openstack Oslo.messagingAI | 4/6/2026 | 27/8/2026 | An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname verification when connecting to the message broker. When ssl_ca_file is configured, the driver enables certificate chain validation but does not pass the expected broker hostname… | |
| Analizada | Alta (8.1) | 0.85% | — | Openstack Ironic | 4/6/2026 | 22/7/2026 | OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. | |
| Analizada | Media (4.9) | 0.47% | — | Openstack Ironic | 4/6/2026 | 22/7/2026 | OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template. | |
| Pendiente de análisis | Crítica (9.9) | 0.92% | — | Openstack MistralAI | 4/6/2026 | 22/7/2026 | OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials. | |
| Modificada | Alta (7.7) | 0.43% | — | Openstack Ironic | 3/6/2026 | 22/7/2026 | OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info. | |
| Aplazada | Media (5.3) | 0.43% | — | Openstack NeutronAI | 28/5/2026 | 21/7/2026 | In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project… | |
| Analizada | Alta (8.1) | 0.32% | — | Openstack Keystone | 28/5/2026 | 17/6/2026 | An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin… | |
| Modificada | Alta (8.8) | 0.43% | — | Openstack Keystone | 28/5/2026 | 23/7/2026 | An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's… | |
| Modificada | Alta (8.8) | 0.42% | — | Openstack Keystone | 28/5/2026 | 23/7/2026 | An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database… | |
| Analizada | Alta (8.8) | 0.40% | — | Openstack Keystone | 28/5/2026 | 17/6/2026 | An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret… | |
| Analizada | Alta (7.1) | 0.36% | — | Openstack Swift | 27/5/2026 | 24/9/2026 | In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with… | |
| Analizada | Media (6.5) | 0.56% | — | Openstack Ironic | 14/5/2026 | 17/6/2026 | In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. | |
| Analizada | Baja (3) | 0.35% | — | Openstack Ironic | 8/5/2026 | 18/6/2026 | In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing. |