Red Hat OpenStack Platform
Red Hat® OpenStack® Platform is a cloud computing platform that virtualizes resources from industry-standard hardware, organizes those resources into clouds, and manages them so users can access what they need—when they need it.
browse_doc
View documentation for Red Hat OpenStack Services on OpenShift.Product Rebranding after 17.1
Release notesRelease information
Deploying Red Hat OpenStack Platform at scalePlanning a Red Hat OpenStack Platform deployment
Installing and managing Red Hat OpenStack Platform with directorInstalling and upgrading Red Hat OpenStack Platform
Customizing your Red Hat OpenStack Platform deploymentCustomizing your Red Hat OpenStack Platform environment
Configuring network functions virtualizationNetwork Functions Virtualization
Configuring spine-leaf networkingData center networking
Configuring Red Hat OpenStack Platform networkingVirtual networking
latest_security
| severity | advisory_cve | synopsis | date |
|---|---|---|---|
| severity Important | advisory_cveCVE-2026-67322 | synopsis A flaw was found in GitPython. A remote attacker can exploit a vulnerability in the Repo.clone_from() method by providing a specially crafted Git repository URL. This URL can contain references to environment variables, which are then expanded and included in the URL. This allows the attacker to exfiltrate sensitive environment variables, such as access keys or tokens, to an attacker-controlled server during the cloning process, leading to information disclosure. | date |
| severity Important | advisory_cveCVE-2026-67325 | synopsis A flaw was found in GitPython. This vulnerability stems from an incomplete command injection blocklist that fails to account for Git's long-option prefix abbreviation feature. An attacker can bypass existing security measures by using abbreviated option names, which Git then resolves to dangerous options. This allows for the execution of arbitrary commands, leading to potential arbitrary code execution. | date |
| severity Important | advisory_cveCVE-2026-44918 | synopsis A flaw was found in OpenStack Ironic. An authenticated project manager can change the node associated with Volume Connectors or Volume Target objects, potentially changing the project permitted to access the object. Volume Connectors contain secrets in environments configuring boot from volume with iSCSI volumes. Additionally, a project manager with the ability to create nodes can use the UUID of a node not owned by their project as a parent node when creating a new node. This mismatched child node can then be used to impact operations on the parent, such as forcing it to power on. | date |
| severity Important | advisory_cve(RHSA-2026:28047) Important: Red Hat OpenStack Platform 17.1 (etcd) security update | synopsis Important: Red Hat OpenStack Platform 17.1 (etcd) security update | date |
| severity Moderate | advisory_cve(RHSA-2026:28046) Moderate: Red Hat OpenStack Platform 17.1 (golang-uber-multierr) security update | synopsis Moderate: Red Hat OpenStack Platform 17.1 (golang-uber-multierr) security update | date |
top_resources
Troubleshooting
Connect to the right information to self-solve issues quickly and efficiently.
Knowledgebase
Access articles and solutions to find answers to your questions.
Labs
Improve performance, troubleshoot issues, identify security problems, and optimize configuration.
Lifecycle
View the various levels of maintenance for each release of a product over a period from initial release to the end of maintenance.