CVE-2018-1078: Opendaylight Openflow
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should be expired or should expire shortly being re-installed and their timers reset resulting in traffic being allowed that should be expired.
Affected products
- Opendaylight Openflow: up to and including carbon; version sp1 only; version sp2 only; version sp3 only
Published 2018-03-16. Last modified 2026-06-17.