Aller au contenu
Kreomnis.Vigie
CVE-2026-94571Critique9.4

In OpenStack Octavia before 18.0.1, multiple TLS/HAProxy config issues allow injection of directives

Publiée le 22/09/2026// Kreomnis Vigie
◆ Veille automatiséeIssue du bulletin du 22/09/2026 · fenêtre 21 septembre 2026sources croisées, relecture Kreomnis
Action recommandée

Mettre à jour OpenStack Octavia vers la série 18.x et appliquer les correctifs liés; revalid­er les ACL L7 et la configuration HAProxy.

Corrections majeures dans OpenStack Octavia 18.0.1 et patches subséquents
2 CVE dans cet advisory
CVSS 4.0
9.4
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS : probabilité d'exploitation
-
Source : FIRST.org, modèle EPSS v3
Produits/versions affectés
  • OpenStack Octavia

Le contexte

Deux CVE dans Octavia (Amphora provider driver) permettent d’injecter des directives HAProxy via des champs TLS/redirect_url/policy. Déploiements utilisant le provider Amphora affectés.

Vecteur d'attaque

Authentifié projet possédant un load balancer TLS manipulant les champs L7 et TLS ciphers.

Systèmes impactés

| Produit | Versions affectées | Versions corrigées | | --- | --- | --- | | OpenStack Octavia | Amphiopa driver TLS configuration ; L7 policy redirect_url/redirect_prefix | 18.0.1 |

Statut du correctif : Corrections majeures dans OpenStack Octavia 18.0.1 et patches subséquents

Les vulnérabilités

CVE-2026-94571 : Control characters handling in L7 policy redirect

OpenStack Octavia (Amphora driver) · CVSS 9.4

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields, allowing injection of HAProxy directives.

Impact : Injection de directives HAProxy via redirect fields.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CVE-2026-94572 : Injection HAProxy directives via TLS/L7 policy

OpenStack Octavia (Amphora driver) · CVSS 9.4

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters; a project member can inject arbitrary HAProxy configuration directives.

Impact : Exécution de directives HAProxy arbitraires sur l’amphora, pouvant modifier le comportement du load balancer.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Recommandations

  • Mettre à jour Octavia vers la version 18.0.1 ou ultérieure.
  • Revoir et nettoyer les politiques L7 et la configuration HAProxy générée.

Ce qu'il faut retenir

Mettre à jour OpenStack Octavia vers la série 18.x et appliquer les correctifs liés; revalid­er les ACL L7 et la configuration HAProxy.

Analyse issue du bulletin de veille Kreomnis du 22 septembre 2026 (fenêtre : 21 septembre 2026). Sources croisées listées ci-dessous.

  • Kreomnis Vigie

Références

#openstack#injection-haproxy-directives#control-characters-handling