cbcvebase.
CVE-2026-50221
published 2026-06-23

CVE-2026-50221: In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host…

PriorityP334medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.15%
4.3th percentile
In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update requests to an attacker-controlled server, enabling server-side request forgery. The SSRF requests expose internal cluster metadata including storage policy indexes, partition mappings, device names, and when at rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key. The attacker can also cause "ghost listings" in arbitrary containers via the shard-range redirect mechanism.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
ansible-automation-platformautomation-portal
ansible-automation-platformbootc-automation-portal-rhel9
openstackswift>= 2.0.0 < 2.35.32.35.3
openstackswift>= 2.36.0 < 2.36.22.36.2
openstackswift>= 2.37.0 < 2.37.22.37.2
rhdhrhdh-hub-rhel9
rhosoopenstack-swift-account-rhel9
rhosoopenstack-swift-base-rhel9
rhosoopenstack-swift-container-rhel9
rhosoopenstack-swift-object-rhel9
rhosoopenstack-swift-proxy-server-rhel9
rhosp-rhel8openstack-swift-account
rhosp-rhel8openstack-swift-base
rhosp-rhel8openstack-swift-container
rhosp-rhel8openstack-swift-object
rhosp-rhel8openstack-swift-proxy-server
rhosp-rhel9openstack-swift-account
rhosp-rhel9openstack-swift-base
rhosp-rhel9openstack-swift-container
rhosp-rhel9openstack-swift-object
rhosp-rhel9openstack-swift-proxy-server
rhosp13openstack-swift-account
rhosp13openstack-swift-base
rhosp13openstack-swift-container
rhosp13openstack-swift-object

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.