CVE-2018-16848: Red Hat Openstack-Mistral

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service.

Affected products

  • Red Hat Openstack-Mistral: up to and including 7.0.3

Published 2020-06-15. Last modified 2026-06-17.