CVE-2026-71191

NameCVE-2026-71191
DescriptionIn OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6449-1
Debian Bugs1142972

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
swift (PTS)bullseye2.26.0-10+deb11u1vulnerable
bullseye (security)2.26.0-10+deb11u2vulnerable
bookworm2.30.1-0+deb12u1vulnerable
bookworm (security)2.30.1-0+deb12u2vulnerable
trixie2.35.1-0+deb13u2vulnerable
trixie (security)2.35.1-0+deb13u3fixed
forky, sid2.37.1-6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
swiftsourcetrixie2.35.1-0+deb13u3DSA-6449-1
swiftsource(unstable)2.37.1-61142972

Notes

https://security.openstack.org/ossa/OSSA-2026-030.html
https://bugs.launchpad.net/swift/+bug/2158733

Search for package or bug name: Reporting problems