freenode

← digests

OpenStack bypasses, NIST HQC formats, and assorted CVEs

Security & Cryptography2026-08-06

OpenStack issued several authorization bypass advisories affecting Swift, Keystone, and Ironic, while NIST advanced a seed-only key format proposal for HQC-KEM and other projects released fixes for memory leaks, account takeovers, and related flaws. Operators of cloud infrastructure, post-quantum libraries, and common servers have multiple patches and draft changes to evaluate.

OpenStack Swift S3API header authorization bypasses

OpenStack Swift announced two S3API header authorization bypass issues under OSSA-2026-030 that permit cross-tenant reads and copies. Patches have been released for the pending CVE. Multi-tenant operators using the S3 API should apply the updates to block unauthorized object access.

NIST seed-only key format for HQC-KEM in FIPS 207

NIST proposed a seed-only key format for HQC-KEM in the upcoming FIPS 207 draft, differing from the dual formats retained for ML-KEM. The change responds to interoperability feedback discussed across 32 messages from 13 participants on the pqc-forum. Implementers preparing post-quantum KEM support should track the divergence for key serialization and migration planning.

OpenStack Keystone LDAP enabled-attribute bypass

CVE-2026-40683 was assigned to OpenStack Keystone because its LDAP identity backend fails to convert the enabled attribute to boolean. The flaw, tracked as OSSA-2026-007, can produce an authentication bypass in multiple releases. Sites relying on LDAP backends need to update affected Keystone versions.

OpenSSL client memory leak in OCSP checking

OpenSSL published low-severity CVE-2026-54876 describing a client-side memory leak during OCSP response checking for stapling verification. The condition may be leveraged for denial of service. Clients that perform OCSP stapling validation should obtain the fix to limit resource exhaustion risk.

ejabberd 26.07 security fixes

ejabberd 26.07 was released with fixes for authentication bypass, SQL injection, and cache poisoning. The changes were announced on oss-security. XMPP server operators should upgrade to close the reported issues.

OpenStack Ironic portgroup shard filter bypass

OpenStack Ironic disclosed CVE-2026-71201 under OSSA-2026-033, in which the shard filter on portgroups bypasses project scope isolation in a manner similar to an earlier ports flaw. The issue weakens tenant separation for bare-metal networking. Ironic deployments should apply the advisory patches to restore project boundaries.

Apache Answer unauthenticated OAuth account takeover

Moderate-severity CVE-2026-48911 was announced for Apache Answer, allowing unauthenticated OAuth email-binding account takeover through the existing user confirmation flow. The problem is fixed in version 2.0.2. Operators of the Q&A platform should move to the patched release.

Jenkins core and plugin vulnerability batch

Jenkins published its regular security advisory listing fixes in core 2.576 and 2.568.2 plus multiple plugins, along with some unresolved issues. The set covers a range of components. Jenkins administrators should review the advisory and apply available updates.