CVE-2026-50221Disclosure(openstack / swift)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update requests to an attacker-controlled server, enabling server-side request forgery. The SSRF requests expose internal cluster metadata including storage policy indexes, partition mappings, device names, and when at rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key. The attacker can also cause "ghost listings" in arbitrary containers via the shard-range redirect mechanism.

0.0/ 10 priority

Sources & remediation

Exploit / PoC references
Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • swift

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
swift

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-25: 1Technical Details · 2026-06-25: 106-25
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Open Source Security mailing list@oss_security
    Disclosure

    OSSA-2026-024: OpenStack Swift: Swift proxy-server SSRF via header injection (CVE-2026-50221) https://www.openwall.com/lists/oss-security/2026/06/23/5

    Post summary

    The post announces a new SSRF vulnerability (CVE‑2026‑50221) in OpenStack Swift’s proxy‑server, describing a header injection flaw that can trigger unintended web requests.

    00000146
    4.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenstackswift---

Explore more