CVE-2026-94571

NameCVE-2026-94571
DescriptionIn OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encodes control characters before validating, and thus newlines passed structural checks, but Octavia stored and wrote the raw unencoded value directly into the HAProxy configuration generated on the amphora. An authenticated project member who owns a load balancer can therefore inject arbitrary HAProxy directives through a REDIRECT_TO_URL L7 policy. Only deployments using the Amphora provider are affected.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1148175

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
octavia (PTS)bookworm11.0.0-2vulnerable
trixie16.0.0-2vulnerable
forky18.0.0-4fixed
sid19.0.0~rc1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
octaviasource(unstable)18.0.0-41148175

Notes

[trixie] - octavia <no-dsa> (Minor issue)
[bookworm] - octavia <postponed> (Minor issue)
https://bugs.launchpad.net/octavia/+bug/2167565
https://bugs.launchpad.net/octavia/+bug/2162101
https://bugs.launchpad.net/octavia/+bug/2162103
https://security.openstack.org/ossa/OSSA-2026-039.html
https://opendev.org/openstack/octavia/commit/cad62902e4984a46ad80cbfa943e90006d8d599d

Search for package or bug name: Reporting problems