CVE-2023-3637: Red Hat Openstack Platform

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

Affected products

  • Red Hat Openstack Platform: version 13.0 only; version 16.2 only

Published 2023-07-25. Last modified 2026-06-17.