Bug 2538157 (CVE-2026-94571)
| Summary: | CVE-2026-94571 openstack-octavia: octavia: HAProxy configuration injection via L7 policy redirect_url and redirect_prefix | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | eglynn, jjoyce, jpretori, jschluet, lhh, mburns, mgarciac |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in OpenStack Octavia. An authenticated user who can create or update L7 policies on their own load balancer can inject arbitrary HAProxy configuration directives through the redirect_url or redirect_prefix fields. The URL validator does not reject control characters such as tabs and newlines, and the raw input is written directly into the HAProxy configuration file on the Amphora VM. This can be used to change redirect behavior and, by injecting HAProxy program directives, to run commands on the Amphora.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-22 17:20:01 UTC
|