<Vulnerability name="CVE-2026-50221">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-06-23T17:03:32</PublicDate>
    <Bugzilla id="2491876" url="https://bugzilla.redhat.com/show_bug.cgi?id=2491876" xml:lang="en:us">
openstack-swift: OpenStack Swift: SSRF via internal update header injection in proxy-server
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>6.4</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-918</CWE>
    <Details xml:lang="en:us" source="Mitre">
In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update requests to an attacker-controlled server, enabling server-side request forgery. The SSRF requests expose internal cluster metadata including storage policy indexes, partition mappings, device names, and when at rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key. The attacker can also cause "ghost listings" in arbitrary containers via the shard-range redirect mechanism.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in OpenStack Swift's proxy-server. Internal container update routing headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) are not stripped from client requests before being forwarded to object-servers. An authenticated user with write access can inject these headers to redirect internal container update requests to an attacker-controlled server, resulting in server-side request forgery. This can lead to disclosure of internal cluster metadata and, when at-rest encryption is enabled, exposure of encrypted container-level key material. Additionally, the attacker can create unauthorized listings in arbitrary containers via the shard-range redirect mechanism.
    </Details>
    <Statement xml:lang="en:us">
Red Hat OpenStack Platform 13, 16.2, 17.1, and Red Hat OpenStack Services on OpenShift 18.0 ship OpenStack Swift proxy-server in affected versions and are vulnerable to this flaw. This vulnerability is rated as Moderate severity because exploitation requires an authenticated user with write access to at least one Swift container. The SSRF allows redirection of container update requests to attacker-controlled servers, exposing internal cluster metadata. When at-rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key are also exposed, though the encryption key itself is not directly disclosed. The attack is network-accessible but requires valid credentials and write permissions, limiting the attacker population to existing tenants within the deployment.
    </Statement>
    <Mitigation xml:lang="en:us">
There is no mitigation for this flaw. The only resolution is to upgrade OpenStack Swift to a patched version: 2.35.3 (for the 2.0.0+ series), 2.36.2 (for the 2.36.x series), or 2.37.2 (for the 2.37.x series). The risk is partially limited because exploitation requires an authenticated user with write access to at least one Swift container.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:rhdh:1">
        <ProductName>Red Hat Developer Hub</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhdh/rhdh-hub-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:13">
        <ProductName>Red Hat OpenStack Platform 13 (Queens)</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>rhosp13/openstack-swift-account</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:13">
        <ProductName>Red Hat OpenStack Platform 13 (Queens)</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>rhosp13/openstack-swift-base</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:13">
        <ProductName>Red Hat OpenStack Platform 13 (Queens)</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>rhosp13/openstack-swift-container</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:13">
        <ProductName>Red Hat OpenStack Platform 13 (Queens)</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>rhosp13/openstack-swift-object</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:13">
        <ProductName>Red Hat OpenStack Platform 13 (Queens)</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>rhosp13/openstack-swift-proxy-server</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:16.2">
        <ProductName>Red Hat OpenStack Platform 16.2</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openstack-swift</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:16.2">
        <ProductName>Red Hat OpenStack Platform 16.2</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhosp-rhel8/openstack-swift-account</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:16.2">
        <ProductName>Red Hat OpenStack Platform 16.2</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhosp-rhel8/openstack-swift-base</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:16.2">
        <ProductName>Red Hat OpenStack Platform 16.2</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhosp-rhel8/openstack-swift-container</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:16.2">
        <ProductName>Red Hat OpenStack Platform 16.2</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhosp-rhel8/openstack-swift-object</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:16.2">
        <ProductName>Red Hat OpenStack Platform 16.2</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhosp-rhel8/openstack-swift-proxy-server</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:17.1">
        <ProductName>Red Hat OpenStack Platform 17.1</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openstack-swift</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:17.1">
        <ProductName>Red Hat OpenStack Platform 17.1</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhosp-rhel9/openstack-swift-account</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:17.1">
        <ProductName>Red Hat OpenStack Platform 17.1</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhosp-rhel9/openstack-swift-base</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:17.1">
        <ProductName>Red Hat OpenStack Platform 17.1</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhosp-rhel9/openstack-swift-container</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:17.1">
        <ProductName>Red Hat OpenStack Platform 17.1</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhosp-rhel9/openstack-swift-object</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:17.1">
        <ProductName>Red Hat OpenStack Platform 17.1</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhosp-rhel9/openstack-swift-proxy-server</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:18.0">
        <ProductName>Red Hat OpenStack Platform 18.0</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openstack-swift</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:18.0">
        <ProductName>Red Hat OpenStack Platform 18.0</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhoso/openstack-swift-account-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:18.0">
        <ProductName>Red Hat OpenStack Platform 18.0</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhoso/openstack-swift-base-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:18.0">
        <ProductName>Red Hat OpenStack Platform 18.0</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhoso/openstack-swift-container-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:18.0">
        <ProductName>Red Hat OpenStack Platform 18.0</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhoso/openstack-swift-object-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:18.0">
        <ProductName>Red Hat OpenStack Platform 18.0</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhoso/openstack-swift-proxy-server-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ansible_portal:2">
        <ProductName>Self-service automation portal 2</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>ansible-automation-platform/automation-portal</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ansible_portal:2">
        <ProductName>Self-service automation portal 2</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>ansible-automation-platform/bootc-automation-portal-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-50221
https://nvd.nist.gov/vuln/detail/CVE-2026-50221
https://launchpad.net/bugs/2150261
https://security.openstack.org/ossa/OSSA-2026-024.html
https://www.openwall.com/lists/oss-security/2026/06/23/5
    </References>
</Vulnerability>