CVE-2026-71190

NameCVE-2026-71190
DescriptionIn OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The "qdtext" pattern (?:[^"]|\\.)* allows an unauthenticated remote attacker to send a crafted Accept header that causes exponential CPU consumption in the proxy worker. A payload of 32 backslash-character pairs exceeds 30 seconds of CPU time. No authentication is required. Repeated requests can exhaust all proxy worker threads, resulting in a complete denial of service.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4746-1
Debian Bugs1142973

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
swift (PTS)bullseye2.26.0-10+deb11u1vulnerable
bullseye (security)2.26.0-10+deb11u2vulnerable
bookworm2.30.1-0+deb12u1vulnerable
bookworm (security)2.30.1-0+deb12u2fixed
trixie2.35.1-0+deb13u2vulnerable
trixie (security)2.35.1-0+deb13u3vulnerable
forky, sid2.37.1-6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
swiftsourcebookworm2.30.1-0+deb12u2DLA-4746-1
swiftsource(unstable)2.37.1-61142973

Notes

[trixie] - swift <no-dsa> (Minor issue)
https://security.openstack.org/ossa/OSSA-2026-031.html
https://bugs.launchpad.net/swift/+bug/2158771

Search for package or bug name: Reporting problems