Follow @Openwall on Twitter for new release announcements and other news
[<prev] [day] [month] [year] [list]
Message-ID: <85249762-8ba9-4ea6-8f88-0079ccbfd79d@gmail.com>
Date: Thu, 23 Jul 2026 12:45:07 -0700
From: Goutham Pacha Ravi <gouthampravi@...il.com>
To: oss-security@...ts.openwall.com
Subject: [OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone
 authentication (CVE-2026-pending)

=======================================================================
OSSA-2026-029: Zaqar EXTRA-SPEC header bypasses Keystone authentication
=======================================================================

:Date: July 23, 2026
:CVE: CVE-2026-pending


Affects
~~~~~~~
- Zaqar: >=12.0.0 <20.1.1, ==21.0.0, ==22.0.0


Description
~~~~~~~~~~~
Chen YuXiang from the Institute of Computing Technology, Chinese
Academy of Sciences reported that the Zaqar messaging service
bypasses Keystone authentication when an EXTRA-SPEC header is
present in the request. An unauthenticated attacker who knows a
project UUID can read, enumerate, create, and delete that project's
queues without a Keystone token. The EXTRA-SPEC header was intended
to support an alternative authentication mechanism, but the backend
validation was never implemented, resulting in a complete
authentication bypass. All deployments running Zaqar 12.0.0 or
later are affected.


Patches
~~~~~~~
- https://review.opendev.org/998272 (2026.2/hibiscus (development))
- https://review.opendev.org/998400 (2026.1/gazpacho)
- https://review.opendev.org/998410 (2025.2/flamingo)
- https://review.opendev.org/998411 (2025.1/epoxy)


Credits
~~~~~~~
- Chen YuXiang from Institute of Computing Technology, Chinese Academy 
of Sciences


References
~~~~~~~~~~
- https://launchpad.net/bugs/2161254
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending


Notes
~~~~~
- A CVE assignment is pending from MITRE. This advisory will be updated
   when the CVE is assigned.
- https://review.opendev.org/998223 proposes removing the EXTRA-SPEC
   feature entirely as a follow-up hardening measure.

--
Goutham Pacha Ravi
OpenStack Vulnerability Management Team
https://security.openstack.org/vmt.html

Download attachment "OpenPGP_0x0638DAD3B82C3988.asc" of type "application/pgp-keys" (3241 bytes)

Download attachment "OpenPGP_signature.asc" of type "application/pgp-signature" (841 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.