Swift OpenStack Swift

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in OpenStack Swift.

By the Year

In 2026 there have been 5 vulnerabilities in OpenStack Swift with an average score of 6.9 out of ten. Swift did not have any published security vulnerabilities last year. That is, 5 more vulnerabilities have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 5 6.90
2025 0 0.00
2024 0 0.00
2023 1 6.50
2022 0 0.00
2021 1 0.00

It may take a day or so for new Swift vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent OpenStack Swift Security Vulnerabilities

OpenStack Swift S3API s3_acl=true header injection bypass (2.38.0)
CVE-2026-71192 6 - Medium - August 05, 2026

In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An attacker can inject these headers into a signed PUT request targeting their own bucket, causing Swift to perform a server-side copy from another tenant's private object. The source object authorization is bypassed because the S3API middleware has already authorized the request against the destination. The attacker can read any object whose project_id, container name, and object name are known, regardless of the source object's ACLs or ownership. This requires the non-default s3_acl=true configuration.

AuthZ

OpenStack Swift 2.38.0 S3API SigV4 Header Injection (CVE-2026-71191)
CVE-2026-71191 6 - Medium - August 05, 2026

In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.

AuthZ

OpenStack Swift 2.38.0 ReDoS in Proxy Accept Header Parser (CVE-2026-71190)
CVE-2026-71190 8.7 - High - August 05, 2026

In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The "qdtext" pattern (?:[^"]|\\.)* allows an unauthenticated remote attacker to send a crafted Accept header that causes exponential CPU consumption in the proxy worker. A payload of 32 backslash-character pairs exceeds 30 seconds of CPU time. No authentication is required. Repeated requests can exhaust all proxy worker threads, resulting in a complete denial of service.

ReDoS

OpenStack Swift <2.37.2 SSRF via Authenticated Header Injection
CVE-2026-50221 - June 23, 2026

In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update requests to an attacker-controlled server, enabling server-side request forgery. The SSRF requests expose internal cluster metadata including storage policy indexes, partition mappings, device names, and when at rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key. The attacker can also cause "ghost listings" in arbitrary containers via the shard-range redirect mechanism.

SSRF

OpenStack Swift s3api infinite loop causes DoS (pre 2.36.2/2.37.2)
CVE-2026-49017 - May 27, 2026

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0.

Infinite Loop

OpenStack Swift S3 API XML Disclosure (before 2.28.1/2.29.2)
CVE-2022-47950 6.5 - Medium - January 18, 2023

An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).

Files or Directories Accessible to External Parties

In OpenStack Swift through 2.10.1
CVE-2017-8761 - June 02, 2021

In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.

OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which
CVE-2016-0738 7.5 - High - January 29, 2016

OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.

Resource Management Errors

OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which
CVE-2016-0737 7.5 - High - January 29, 2016

OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.

Resource Management Errors

Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1
CVE-2014-3497 - July 03, 2014

Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.

OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which
CVE-2012-4406 - October 22, 2012

OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for OpenStack Swift or by OpenStack? Click the Watch button to subscribe.

OpenStack
Vendor

subscribe