CVE-2026-71191: Openstack Swift
Medium severity, CVSS 6.0. EPSS: 0.6% chance of exploitation in the next 30 days.
In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.
Affected products
- Openstack Swift: from 2.18.0, before 2.35.4 (fixed in 2.35.4); from 2.36.0, before 2.36.3 (fixed in 2.36.3); from 2.37.0, before 2.37.3 (fixed in 2.37.3); version 2.38.0 only
Published 2026-08-05. Last modified 2026-09-09.