Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vxvf-xvm3-p8j5 | OpenStack Horizon has Incorrect Behavior Order |
Wed, 06 May 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 05 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OpenStack Horizon Session Storage Exhaustion Vulnerability |
Tue, 05 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix. | |
| First Time appeared |
Openstack
Openstack horizon |
|
| Weaknesses | CWE-696 | |
| CPEs | cpe:2.3:a:openstack:horizon:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack horizon |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-06T06:05:23.992Z
Reserved: 2026-05-01T00:00:00.000Z
Link: CVE-2026-43002
Updated: 2026-05-05T17:26:49.397Z
Status : Awaiting Analysis
Published: 2026-05-05T17:17:04.920
Modified: 2026-05-07T15:53:49.717
Link: CVE-2026-43002
No data.
OpenCVE Enrichment
Updated: 2026-05-05T19:00:12Z
Github GHSA