Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-49017

Опубликовано: 27 мая 2026
Источник: redhat
CVSS3: 6.5

Описание

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0.

A flaw was found in OpenStack Swift. An authenticated attacker can exploit this vulnerability by sending a specially crafted, truncated aws-chunked PUT request body to the s3api middleware. This action causes an infinite loop within the StreamingInput class, leading to the affected proxy-server worker becoming unresponsive. Consequently, an attacker can exhaust all available proxy-server workers, resulting in a Denial of Service (DoS) for the system.

Меры по смягчению последствий

If S3 API compatibility is not required, the s3api middleware can be disabled in the Swift proxy server configuration. This action will prevent the exploitation of this vulnerability by removing the affected functionality. Disabling s3api will remove S3 API support for OpenStack Swift, which may impact services relying on this functionality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 16.2openstack-swiftFix deferred
Red Hat OpenStack Platform 17.1openstack-swiftFix deferred
Red Hat OpenStack Platform 18.0openstack-swiftFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2481759openstack-swift: OpenStack Swift: Denial of Service via truncated aws-chunked PUT request

6.5 Medium

CVSS3

Связанные уязвимости

ubuntu
2 месяца назад

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0.

nvd
2 месяца назад

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0.

debian
2 месяца назад

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters a ...

github
2 месяца назад

OpenStack Swift: s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body

6.5 Medium

CVSS3