OpenStack advisories, Go HTTP/2 fixes, PQC attack claims
OpenStack published authorization and credential-handling advisories for Mistral and Ironic, while the Go project shipped point releases and an x/net update for HTTP/2 flaws. Post-quantum discussions focused on claimed attacks against Classic McEliece and artificial LWE parameters, plus modeling questions for two signature candidates.
OpenStack Mistral authorization vulnerabilities
OpenStack Security Advisory OSSA-2026-044 discloses four authorization and privilege vulnerabilities in Mistral, tracked as CVE-2026-93858, CVE-2026-93860, CVE-2026-93861, and CVE-2026-97147. The flaws permit cross-project resource writes and ownership changes. Operators running Mistral workflows need the patches to block privilege escalation across projects.
HTTP/2 memory exhaustion in golang.org/x/net
The Go team reported an HTTP/2 memory exhaustion issue in golang.org/x/net that can be triggered by malicious Trailer headers and is fixed in v0.60.0. Services that pull this module for HTTP/2 handling are exposed to denial-of-service from crafted requests. Updating the dependency closes the vector.
Go 1.27.2 and 1.26.9 security releases
Go 1.27.2 and Go 1.26.9 were released to address 15 security issues, among them an HTTP/2 server crash caused by an unsynchronized HPACK encoder. The point releases deliver fixes across the toolchain. Users should move to the new versions to obtain the corrections.
OpenJPEG heap-buffer-overflow still in releases
A heap-buffer-overflow write in OpenJPEG was fixed on the master branch in February 2026 yet remains present in every published release, including 2.5.3 and 2.5.4. The issue was posted to oss-security without an assigned CVE. Applications that depend on released OpenJPEG builds for JPEG 2000 decoding stay vulnerable until a new tarball appears.
OpenStack Ironic basic-auth credential leak
OpenStack Security Note OSSN-0110 describes how Ironic can leak basic authentication credentials to an image server when certain image_server_auth settings are used. Under those configurations the credentials may reach arbitrary hosts. Administrators should audit Ironic image-server authentication options.
Quasipolynomial claims against Classic McEliece
A new eprint asserts a quasipolynomial distinguisher and heuristic decryption attack on Classic McEliece, prompting an extended PQC forum thread that also includes a disclosure dispute involving Apon. Participants are examining the practical strength of the claimed break against the code-based scheme. The discussion remains heated and unresolved on impact.
Subexponential LWE claims for artificial parameters
PQC researchers reviewed an eprint claiming subexponential LWE attacks with complexity on the order of 2^(n/loglog n) for tiny-noise artificial parameter sets. Forum consensus is that the results do not affect standardized schemes. The attacks apply only to contrived instances outside normal cryptographic use.
Ideal Cipher Model questions for SDitH and MQOM
A Round 3 additional-signatures comment thread on the PQC forum challenges Ideal Cipher Model assumptions for AES and Rijndael as used by the SDitH and MQOM signature candidates. The exchange probes whether those modeling choices are justified. Submitters and reviewers continue to weigh the security arguments.