CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-71191

unknowncovered by 2 sourcesfirst seen 2026-08-05
In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.

CSIRTS triage

What
Swift distributed virtual object store contains SSRF vulnerability and s3api middleware authorization bypass.
Who is affected
Deployments using Swift object store, especially those using s3api middleware.
Urgency
High urgency due to authorization bypass and information disclosure via SSRF.
Action
Apply DSA-6449-1 security update to Swift.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-71191

Get an email if CVE-2026-71191 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-71191

CVE.org record

Embed the live status

CVE-2026-71191 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-71191 status](https://www.csirts.com/badge/CVE-2026-71191)](https://www.csirts.com/cve/CVE-2026-71191)