What is CVE-2026-71192?
In OpenStack Swift through version 2.38.0, the S3API middleware does not sanitize Swift-native control headers like X-Copy-From from S3 API requests when s3_acl=true. An attacker can inject these headers into a signed PUT request targeting their own bucket, leading to an internal server-side copy operation. Affected users should restrict S3 API access and upgrade Swift to the latest patched version.
Azərbaycanca: OpenStack Swift-in 2.38.0 versiyasına qədər S3API middleware-i, s3_acl aktiv olduqda, S3 sorğularından Swift-ə məxsus X-Copy-From kimi nəzarət başlıqlarını təmizləmir. Təcavüzkar öz bucket-ına imzalanmış PUT sorğusuna bu başlıqları yeridərək serverdaxili surətçıxarma əməliyyatına səbəb ola bilər. Təsirlənən sistemlərdə S3 API girişini məhdudlaşdırmaq və Swift-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: OpenStack
FAQ2
In which component of OpenStack Swift does CVE-2026-71192 exist?
The vulnerability exists in the S3API middleware of OpenStack Swift through version 2.38.0 when s3_acl is enabled (s3_acl=true).
What operation can an attacker perform by exploiting this vulnerability?
An attacker can inject Swift-native control headers like X-Copy-From into a signed PUT request targeting their own bucket, leading to an internal server-side copy operation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.