CVE-2026-97149
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, and path, and thus the list of disallowed headers is the only defense against a signed PUT request changing what the request does. An attacker holding a PUT TempURL for a single object can add an X-Copy-From header naming any object in the same account; the copy middleware copies that object to the destination, and the attacker then reads the victim's data back with a GET TempURL for the destination object. Copies across account boundaries are rejected. Only deployments using the shipped default proxy pipeline (tempurl and copy middleware) with account-level TempURL keys are affected.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenStack | Swift | 2.4.0 < 2.35.5 | affected |
| OpenStack | Swift | 2.36.0 < 2.36.4 | affected |
| OpenStack | Swift | 2.37.0 < 2.37.4 | affected |
| OpenStack | Swift | 2.38.0 < 2.38.2 | affected |
Weaknesses
- CWE-184: CWE-184 Incomplete List of Disallowed Inputs
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.