
OSSA-2026-009,CVE-2026-43002: OpenStack Horizon: Unauthenticated session flood via login redirect storage https://www.openwall.com/lists/oss-security/2026/05/05/7 The login view stores a post-login redirect URL in the server-side session before the user authenticates. Attacker can exhaust the session storage.
Post summary
This brief notice discloses that OpenStack Horizon's login process can be abused to flood session storage by storing redirect URLs before authentication.


