# CVE-2026-94571 : In OpenStack Octavia before 18.0.1, multiple TLS/HAProxy config issues allow injection of directives

> Deux CVE dans Octavia (Amphora provider driver) permettent d’injecter des directives HAProxy via des champs TLS/redirect_url/policy. Déploiements utilisant le provider Amphora affectés.

- Page canonique : https://kreomnisvigie.com/cve/cve-2026-94571-openstack
- Sévérité : Critique · CVSS 9.4 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CISA KEV (exploitation observée) : non
- Éditeur : OpenStack
- Produits : OpenStack Octavia
- Correctif disponible : oui · PoC public : non · Exploitée : non
- Publiée le 22 septembre 2026 · Kreomnis Vigie
- Issue du bulletin du 22 septembre 2026 (21 septembre 2026)
- Mots clés : openstack, injection-haproxy-directives, control-characters-handling

## Action recommandée

Mettre à jour OpenStack Octavia vers la série 18.x et appliquer les correctifs liés; revalid­er les ACL L7 et la configuration HAProxy.

## 2 CVE dans cet advisory

- CVE-2026-94572 (OpenStack Octavia (Amphora driver)) · CVSS 9.4 : Injection HAProxy directives via TLS/L7 policy
- CVE-2026-94571 (OpenStack Octavia (Amphora driver)) · CVSS 9.4 : Control characters handling in L7 policy redirect

## Le contexte

Deux CVE dans Octavia (Amphora provider driver) permettent d’injecter des directives HAProxy via des champs TLS/redirect_url/policy. Déploiements utilisant le provider Amphora affectés.

## Vecteur d'attaque

Authentifié projet possédant un load balancer TLS manipulant les champs L7 et TLS ciphers.

## Systèmes impactés

| Produit | Versions affectées | Versions corrigées |
| --- | --- | --- |
| OpenStack Octavia | Amphiopa driver TLS configuration ; L7 policy redirect_url/redirect_prefix | 18.0.1 |

Statut du correctif : Corrections majeures dans OpenStack Octavia 18.0.1 et patches subséquents

## Les vulnérabilités

### CVE-2026-94571 : Control characters handling in L7 policy redirect

OpenStack Octavia (Amphora driver) · CVSS 9.4

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields, allowing injection of HAProxy directives.

Impact : Injection de directives HAProxy via redirect fields.

`CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X`

### CVE-2026-94572 : Injection HAProxy directives via TLS/L7 policy

OpenStack Octavia (Amphora driver) · CVSS 9.4

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters; a project member can inject arbitrary HAProxy configuration directives.

Impact : Exécution de directives HAProxy arbitraires sur l’amphora, pouvant modifier le comportement du load balancer.

`CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X`

## Recommandations

- Mettre à jour Octavia vers la version 18.0.1 ou ultérieure.
- Revoir et nettoyer les politiques L7 et la configuration HAProxy générée.

## Ce qu'il faut retenir

Mettre à jour OpenStack Octavia vers la série 18.x et appliquer les correctifs liés; revalid­er les ACL L7 et la configuration HAProxy.

Analyse issue du bulletin de veille Kreomnis du 22 septembre 2026 (fenêtre : 21 septembre 2026). Sources croisées listées ci-dessous.

- Kreomnis Vigie

## Références

- [GitHub Advisories](https://github.com/advisories) (vendor)
- [ghsa — In OpenStack Octavia before 18.0.1, the Amphora provider driver did not…](https://github.com/advisories/GHSA-xwpf-r3rp-gx2r) (vendor)
- [CVE-2026-94571 : source primaire](https://github.com/advisories/GHSA-33h9-ppgm-5785) (nvd)

Source : Kreomnis Vigie, https://kreomnisvigie.com/cve/cve-2026-94571-openstack. Analyse à usage défensif uniquement.
