CVE-2026-46448
Affects
- Nova: >=18.0.0 <31.3.1, >=32.0.0 <32.2.1, >=33.0.0 <33.0.2
Description
Erichen from the Institute of Computing Technology, Chinese Academy of
Sciences reported that Nova's server create API does not strip internal
scheduler hints. An authenticated user can bypass Placement resource
claims and scheduling constraint enforcement, including availability
zone, host aggregate, and image trait restrictions. The resulting
instance has no Placement allocation, which can lead to compute node
resource exhaustion and cross-tenant data persistence on NVMe devices
after instance deletion. Deployments running Nova 18.0.0 or later are
affected.
Patches
- https://review.opendev.org/993604 (2025.1/epoxy)
- https://review.opendev.org/993603 (2025.2/flamingo)
- https://review.opendev.org/993602 (2026.1/gazpacho)
- https://review.opendev.org/993601 (2026.2/hibiscus)
Credits
- Erichen from Institute of Computing Technology, Chinese Academy of
Sciences (CVE-2026-46448)
⚡ Watch CVE-2026-46448
Get an email if CVE-2026-46448 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
Advisory coverage (1)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-46448)