CVE-2018-1078: Opendaylight Openflow

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should be expired or should expire shortly being re-installed and their timers reset resulting in traffic being allowed that should be expired.

Affected products

  • Opendaylight Openflow: up to and including carbon; version sp1 only; version sp2 only; version sp3 only

Published 2018-03-16. Last modified 2026-06-17.