openstack
15 known vulnerabilities affecting openstack products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2013-0335 | Medium | 2.1% | 7.6 | OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows rem… | |
| CVE-2026-43003 | Medium | 1.0% | 8.0 | An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. I… | |
| CVE-2026-43001 | Medium | 0.5% | 7.9 | An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credential… | |
| CVE-2026-42997 | Medium | 0.4% | 7.7 | An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During impor… | |
| CVE-2013-0270 | Low | 3.2% | 6.5 | A flaw was found in OpenStack Keystone. A remote attacker could exploit this vul… | |
| CVE-2017-7200 | Low | 2.1% | 5.8 | An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' … | |
| CVE-2026-48681 | Low | 0.6% | 5.9 | OpenStack Ironic through before 35.0.2 allows file overwrite via directory trave… | |
| CVE-2026-42510 | Low | 0.6% | 6.6 | OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default config… | |
| CVE-2026-50589 | Low | 0.4% | 5.3 | In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could su… | |
| CVE-2026-43002 | Low | 0.4% | 5.3 | An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There … | |
| CVE-2026-42999 | Low | 0.3% | 6.0 | An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC p… | |
| CVE-2026-43000 | Low | 0.3% | 6.0 | An issue was discovered in OpenStack Keystone before 29.0.2. When combined with … | |
| CVE-2026-44917 | Low | 0.3% | 4.9 | OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or… | |
| CVE-2026-34881 | Low | 0.3% | 5.0 | OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Se… | |
| CVE-2026-46447 | Low | 0.3% | 5.8 | OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if… |