CVE-2026-97149
Description
A flaw was found in OpenStack Swift's tempurl middleware. A TempURL is a signed, time-limited link that should allow access to only one object. The signature does not cover extra request headers, and Swift did not block the X-Copy-From header on these signed upload requests. An attacker who already holds a valid upload TempURL for one object can name another object in the same account. Swift copies that object's contents into the allowed destination, and the attacker can then download it. This exposes data the TempURL was not meant to grant. The attacker must know the other object's container and name, and the copy cannot cross into a different account. Only deployments that use the tempurl middleware are affected.
Statement
This vulnerability is rated Moderate because a party who already holds a valid upload TempURL can read other objects in the same Swift account. The attack does not cross into another account, does not allow code execution, and requires the attacker to know the target container and object name. The tempurl middleware must be enabled. That middleware is part of the default Swift proxy pipeline.
The following Red Hat products ship openstack-swift builds that contain the vulnerable code and are affected: Red Hat OpenStack Platform 13 (openstack-swift 2.17.1), Red Hat OpenStack Platform 16.2 (openstack-swift 2.23.4), Red Hat OpenStack Platform 17.1 (openstack-swift 2.27.1), and Red Hat OpenStack Services on OpenShift 18 (openstack-swift 2.31.2).
Ansible Automation Platform and Red Hat Developer Hub are not affected. Name matches in those products are a JavaScript client library for Swift, not the Swift service.
Mitigation
Until a product update is available, operators can drop the dangerous header in the proxy configuration. In the [filter:tempurl] section, add x-copy-from to the incoming_remove_headers option. Swift then removes the header, and the signed upload does not copy another object. This applies only where the tempurl middleware is enabled. If TempURL is not required, leaving that middleware out of the proxy pipeline also avoids the issue.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 6.5 | N/A | N/A |
| Attack Vector | Network | N/A | N/A |
| Attack Complexity | Low | N/A | N/A |
| Privileges Required | Low | N/A | N/A |
| User Interaction | None | N/A | N/A |
| Scope | Unchanged | N/A | N/A |
| Confidentiality | High | N/A | N/A |
| Integrity Impact | None | N/A | N/A |
| Availability Impact | None | N/A | N/A |
Vector
Red Hat: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Red Hat CVSS v3 Score Explanation
Re-evaluated against OSSA-2026-041. AV:N because the attack is a crafted HTTP request to the Swift proxy. AC:L because a party who already holds a signed PUT TempURL can repeat the request with an extra header. Knowing the object name is part of the request, not a rare precondition. PR:L because a valid single-object TempURL is required and full account credentials are not. UI:N. S:U because copies cannot cross accounts. C:H because the copied object is fully readable. I:N because the source object is not modified and the destination is already writable by that TempURL. A:N. Score remains 6.5. Impact remains MODERATE.
Understanding the Weakness (CWE)
Access Control
Technical Impact: Bypass Protection Mechanism
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.