Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-49017

Опубликовано: 27 мая 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0.

РелизСтатусПримечание
devel

needed

esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
questing

ignored

end of life, was needed
resolute

needed

upstream

released

2.37.2

Показывать по

EPSS

Процентиль: 25%
0.00322
Низкий

Связанные уязвимости

CVSS3: 6.5
redhat
2 месяца назад

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0.

nvd
2 месяца назад

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0.

debian
2 месяца назад

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters a ...

github
2 месяца назад

OpenStack Swift: s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body

EPSS

Процентиль: 25%
0.00322
Низкий