No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 05 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OpenStack Horizon Session Storage Exhaustion Vulnerability |
Tue, 05 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix. | |
| First Time appeared |
Openstack
Openstack horizon |
|
| Weaknesses | CWE-696 | |
| CPEs | cpe:2.3:a:openstack:horizon:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack horizon |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-05T17:26:59.504Z
Reserved: 2026-05-01T00:00:00.000Z
Link: CVE-2026-43002
Updated: 2026-05-05T17:26:49.397Z
Status : Received
Published: 2026-05-05T17:17:04.920
Modified: 2026-05-05T18:16:02.737
Link: CVE-2026-43002
No data.
OpenCVE Enrichment
Updated: 2026-05-05T19:00:12Z