CVE-2026-43002Disclosure(openstack / horizon)

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-696

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • horizon

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
horizon

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-05: 3Technical Details · 2026-05-05: 205-05
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    OSSA-2026-009,CVE-2026-43002: OpenStack Horizon: Unauthenticated session flood via login redirect storage https://www.openwall.com/lists/oss-security/2026/05/05/7 The login view stores a post-login redirect URL in the server-side session before the user authenticates. Attacker can exhaust the session storage.

    Post summary

    This brief notice discloses that OpenStack Horizon's login process can be abused to flood session storage by storing redirect URLs before authentication.

    01081594
    4.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-43002 An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus sto… https://www.cve.org/CVERecord?id=CVE-2026-43002 ----- Traducción: CVE-2026-43002 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑43002 impacting OpenStack Horizon 25.6 and 25.7 before 25.7.3, highlighting an unauthenticated write to session storage, but does not provide further exploit, patch, or PoC details.

    0000084
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-43002 An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus sto… https://www.cve.org/CVERecord?id=CVE-2026-43002

    Post summary

    The post announces CVE‑2026‑43002, noting a pre‑authentication write flaw in OpenStack Horizon’s session storage, without disclosing PoC, exploit code, active usage, or mitigation details.

    00000218
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenstackhorizon---

Explore more