CVE-2016-9185: Openstack Heat

Medium severity, CVSS 4.3. EPSS: 1.5% chance of exploitation in the next 30 days.

In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.

Affected products

  • Openstack Heat: version 5.0.3 only; version 6.0.0 only; version 6.1.0 only; version 7.0.0 only

Published 2016-11-04. Last modified 2026-06-17.