Bug 2538157 (CVE-2026-94571) - CVE-2026-94571 openstack-octavia: octavia: HAProxy configuration injection via L7 policy redirect_url and redirect_prefix
Summary: CVE-2026-94571 openstack-octavia: octavia: HAProxy configuration injection vi...
Keywords:
Status: NEW
Alias: CVE-2026-94571
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-22 17:20 UTC by OSIDB Bzimport
Modified: 2026-09-29 14:10 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-22 17:20:01 UTC
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encodes control characters before validating, and thus newlines passed structural checks, but Octavia stored and wrote the raw unencoded value directly into the HAProxy configuration generated on the amphora. An authenticated project member who owns a load balancer can therefore inject arbitrary HAProxy directives through a REDIRECT_TO_URL L7 policy. Only deployments using the Amphora provider are affected.


Note You need to log in before you can comment on or make changes to this bug.