CVE-2026-59654

Summary

Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects different modules and plugins of the CloudStack management server, including Quota, Host-HA, etc., and may lead to eventual denial of service (DoS) scenario for the management server.

This issue affects Apache CloudStack: from 4.7.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.

Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

Affected Software

VendorProductVersion RangeStatus
Apache Software FoundationApache CloudStack4.7.0 <= 4.20.3.0affected
Apache Software FoundationApache CloudStack4.21.0.0 <= 4.22.1.0affected

Weaknesses

  • CWE-772: CWE-772 Missing Release of Resource after Effective Lifetime

References