CVE-2026-50221
published 2026-06-23CVE-2026-50221: In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host…
PriorityP334medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.15%
4.3th percentile
In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update requests to an attacker-controlled server, enabling server-side request forgery. The SSRF requests expose internal cluster metadata including storage policy indexes, partition mappings, device names, and when at rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key. The attacker can also cause "ghost listings" in arbitrary containers via the shard-range redirect mechanism.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform | automation-portal | — | — |
| ansible-automation-platform | bootc-automation-portal-rhel9 | — | — |
| openstack | swift | >= 2.0.0 < 2.35.3 | 2.35.3 |
| openstack | swift | >= 2.36.0 < 2.36.2 | 2.36.2 |
| openstack | swift | >= 2.37.0 < 2.37.2 | 2.37.2 |
| rhdh | rhdh-hub-rhel9 | — | — |
| rhoso | openstack-swift-account-rhel9 | — | — |
| rhoso | openstack-swift-base-rhel9 | — | — |
| rhoso | openstack-swift-container-rhel9 | — | — |
| rhoso | openstack-swift-object-rhel9 | — | — |
| rhoso | openstack-swift-proxy-server-rhel9 | — | — |
| rhosp-rhel8 | openstack-swift-account | — | — |
| rhosp-rhel8 | openstack-swift-base | — | — |
| rhosp-rhel8 | openstack-swift-container | — | — |
| rhosp-rhel8 | openstack-swift-object | — | — |
| rhosp-rhel8 | openstack-swift-proxy-server | — | — |
| rhosp-rhel9 | openstack-swift-account | — | — |
| rhosp-rhel9 | openstack-swift-base | — | — |
| rhosp-rhel9 | openstack-swift-container | — | — |
| rhosp-rhel9 | openstack-swift-object | — | — |
| rhosp-rhel9 | openstack-swift-proxy-server | — | — |
| rhosp13 | openstack-swift-account | — | — |
| rhosp13 | openstack-swift-base | — | — |
| rhosp13 | openstack-swift-container | — | — |
| rhosp13 | openstack-swift-object | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenStack Swift up to 2.35.2/2.36.1/2.37.1 Encryption Key server-side request forgery
vuldb·2026-06-23·CVSS 5.3
CVE-2026-50221 [MEDIUM] OpenStack Swift up to 2.35.2/2.36.1/2.37.1 Encryption Key server-side request forgery
A vulnerability classified as critical was found in OpenStack Swift up to 2.35.2/2.36.1/2.37.1. This issue affects some unknown processing of the component Encryption Key Handler. Such manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2026-50221. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
GHSA
In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwardin
ghsa_unreviewed·2026-06-23
CVE-2026-50221 [MEDIUM] CWE-918 In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwardin
In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update requests to an attacker-controlled server, enabling server-side request forgery. The SSRF requests expose internal cluster metadata including storage policy indexes, partition mappings, device names, and when at rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key. The attacker can also cause "ghost listings" in arbitrary containers via the shard-range redirect mechanism.
Red Hat
openstack-swift: OpenStack Swift: SSRF via internal update header injection in proxy-server
vendor_redhat·2026-06-23·CVSS 5.3
CVE-2026-50221 [MEDIUM] CWE-918 openstack-swift: OpenStack Swift: SSRF via internal update header injection in proxy-server
openstack-swift: OpenStack Swift: SSRF via internal update header injection in proxy-server
A flaw was found in OpenStack Swift's proxy-server. Internal container update routing headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) are not stripped from client requests before being forwarded to object-servers. An authenticated user with write access can inject these headers to redirect internal container update requests to an attacker-controlled server, resulting in server-side request forgery. This can lead to disclosure of internal cluster metadata and, when at-rest encryption is enabled, exposure of encrypted container-level key material. Additionally, the attacker can create unauthorized listings in arbitrary containers via the shard-range redirect mecha
No detection rules found.
No public exploits indexed.
2026-06-23
Published