Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2577▼ 295 respecto a la semana anterior
Críticas / altas1354▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
81 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.6) | 0.55% | — | Openstack KeystoneAI | 11/9/2026 | 22/9/2026 | An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or deleting credentials via the /v3/credentials API. EC2-derived tokens can… | |
| Pendiente de análisis | Alta (7.1) | 0.38% | — | Openstack KeystoneAI | 27/8/2026 | 9/9/2026 | In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing… | |
| Pendiente de análisis | Alta (7.6) | 0.60% | — | Openstack KeystoneAI | 25/8/2026 | 3/9/2026 | In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) could be submitted to the token-method authentication path for reauthentication to escape their intended project scope. When an application credential token was presented… | |
| Pendiente de análisis | Alta (7.6) | 0.57% | — | Openstack KeystoneAI | 25/8/2026 | 9/9/2026 | In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain them. The delegation restrictions that… | |
| Aplazada | Alta (7.5) | 0.67% | — | KeystoneAI | 21/8/2026 | 9/9/2026 | Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core/queries/resolvers.ts compares the signed take argument directly with graphql.maxTake, allowing a remote unauthenticated GraphQL client to provide a negative take value whose magnitude exceeds the… | |
| Aplazada | Baja (2.1) | 0.31% | — | Keystonejs KeystoneAI | 4/6/2026 | 22/7/2026 | A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/core/queries/output-field.ts of the component GraphQL API Endpoint. The manipulation results in resource consumption. It is possible to launch the attack remotely. The… | |
| Analizada | Alta (8.1) | 0.32% | — | Openstack Keystone | 28/5/2026 | 17/6/2026 | An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin… | |
| Modificada | Alta (8.8) | 0.43% | — | Openstack Keystone | 28/5/2026 | 23/7/2026 | An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's… | |
| Modificada | Alta (8.8) | 0.42% | — | Openstack Keystone | 28/5/2026 | 23/7/2026 | An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database… | |
| Analizada | Alta (8.8) | 0.40% | — | Openstack Keystone | 28/5/2026 | 17/6/2026 | An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret… | |
| Modificada | Alta (8) | 0.59% | — | Openstack Keystone | 1/5/2026 | 14/8/2026 | An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to… | |
| Pendiente de análisis | Alta (7.7) | 0.37% | — | Openstack KeystoneAI | 14/4/2026 | 5/8/2026 | In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was… | |
| Analizada | Media (5.3) | 0.33% | — | Openstack Keystone | 10/4/2026 | 17/6/2026 | An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3… | |
| Analizada | Media (4.3) | 0.28% | — | Keystonejs Keystone | 24/3/2026 | 17/6/2026 | Keystone is a content management system for Node.js. Prior to version 6.5.2, {field}.isFilterable access control can be bypassed in findMany queries by passing a cursor. This can be used to confirm the existence of records by protected field values. The fix for CVE-2025-46720 (field-level isFilterable bypass for… | |
| Aplazada | Crítica (9.9) | 0.66% | — | Openstack KeystonemiddlewareAI | 19/1/2026 | 10/9/2026 | An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers… | |
| Aplazada | Alta (7.5) | 0.23% | — | Openstack KeystoneAI | 17/11/2025 | 17/6/2026 | OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. | |
| Analizada | Media (4.3) | 0.28% | — | Keystonejs Keystone | 5/5/2025 | 17/6/2026 | Keystone is a content management system for Node.js. Prior to version 6.5.0, `{field}.isFilterable` access control can be bypassed in `update` and `delete` mutations by adding additional unique filters. These filters can be used as an oracle to probe the existence or value of otherwise unreadable fields. Specifically,… | |
| Modificada | Media (5.3) | 0.58% | — | Keystonejs Keystone | 15/8/2023 | 17/6/2026 | Keystone is an open source headless CMS for Node.js — built with GraphQL and React. When `ui.isAccessAllowed` is set as `undefined`, the `adminMeta` GraphQL query is publicly accessible (no session required). This is different to the behaviour of the default AdminUI middleware, which by default will only be publicly… | |
| Modificada | Media (4.1) | 0.41% | — | Keystonejs Keystone | 13/6/2023 | 17/6/2026 | Keystone is a content management system for Node.JS. There is an open redirect in the `@keystone-6/auth` package versions 7.0.0 and prior, where the redirect leading `/` filter can be bypassed. Users may be redirected to domains other than the relative host, thereby it might be used by attackers to re-direct users to… | |
| Modificada | Crítica (9.8) | 1.6% | — | Keystonejs Keystone | 3/11/2022 | 17/6/2026 | Keystone is a headless CMS for Node.js — built with GraphQL and React.`@keystone-6/core@3.0.0 || 3.0.1` users that use `NODE_ENV` to trigger security-sensitive functionality in their production builds are vulnerable to `NODE_ENV` being inlined to `"development"` for user code, irrespective of what your environment… | |
| Modificada | Crítica (9.8) | 1.2% | — | Keystonejs Keystone | 25/10/2022 | 17/6/2026 | @keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, users who expected their `multiselect` fields to use the field-level access control - if configured - are vulnerable to their field-level access control not being used.… | |
| Modificada | Media (6.6) | 0.72% | — | Openstack KeystoneRedhat Openstack PlatformRedhat QuayRedhat Storage | 1/9/2022 | 17/6/2026 | A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected. | |
| Modificada | Alta (7.4) | 1.7% | — | Openstack KeystoneDebian LinuxRedhat Openstack Platform | 26/8/2022 | 17/6/2026 | A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. | |
| Modificada | Crítica (9.8) | 2.4% | — | Keystonejs Keystone | 16/5/2022 | 17/6/2026 | An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted file. | |
| Modificada | Media (6.1) | 2.6% | — | Keystonejs Keystone | 12/1/2022 | 17/6/2026 | keystone is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |