Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 05 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unsigned X-Amz-Copy-Source Header Injection in OpenStack Swift S3API Presigned URLs |
Wed, 05 Aug 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration. | |
| First Time appeared |
Openstack
Openstack swift |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack swift |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-05T05:01:20.971Z
Reserved: 2026-08-05T05:01:20.566Z
Link: CVE-2026-71191
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T06:30:03Z
-
CWE-863
Incorrect Authorization