CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-71192

unknowncovered by 2 sourcesfirst seen 2026-08-05
In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An attacker can inject these headers into a signed PUT request targeting their own bucket, causing Swift to perform a server-side copy from another tenant's private object. The source object authorization is bypassed because the S3API middleware has already authorized the request against the destination. The attacker can read any object whose project_id, container name, and object name are known, regardless of the source object's ACLs or ownership. This requires the non-default s3_acl=true configuration.

CSIRTS triage

What
Swift distributed virtual object store contains SSRF vulnerability and s3api middleware authorization bypass.
Who is affected
Deployments using Swift object store, especially those using s3api middleware.
Urgency
High urgency due to authorization bypass and information disclosure via SSRF.
Action
Apply DSA-6449-1 security update to Swift.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-71192

Get an email if CVE-2026-71192 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-71192

CVE.org record

Embed the live status

CVE-2026-71192 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-71192 status](https://www.csirts.com/badge/CVE-2026-71192)](https://www.csirts.com/cve/CVE-2026-71192)