CVE-2026-97149: CWE-184 Incomplete List of Disallowed Inputs in OpenStack Swift
In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, and path, and thus the list of disallowed headers is the only defense against a signed PUT request changing what the request does. An attacker holding a PUT TempURL for a single object can add an X-Copy-From header naming any object in the same account; the copy middleware copies that object to the destination, and the attacker then reads the victim's data back with a GET TempURL for the destination object. Copies across account boundaries are rejected. Only deployments using the shipped default proxy pipeline (tempurl and copy middleware) with account-level TempURL keys are affected.
AI Analysis
Technical Summary
In OpenStack Swift versions before 2.38.2, the tempurl middleware fails to reject the X-Copy-From header on PUT requests. TempURL signatures protect only the HTTP method, expiry, and path, relying on a list of disallowed headers to prevent unauthorized request modifications. An attacker possessing a PUT TempURL for one object can add an X-Copy-From header referencing any other object in the same account, causing the copy middleware to duplicate that object to the destination. The attacker can then retrieve the copied data using a GET TempURL for the destination object. This vulnerability affects only deployments using the default proxy pipeline with account-level TempURL keys and does not allow copying across account boundaries.
Potential Impact
An attacker with a valid PUT TempURL for a single object can exploit this vulnerability to copy any object within the same account, potentially exposing sensitive data. The attacker can then read the copied data using a GET TempURL. This bypasses the intended security controls of TempURL signatures, leading to unauthorized data access within the same account. Cross-account data access is not possible, limiting the impact to objects within the attacker's account.
Mitigation Recommendations
A fix is available in OpenStack Swift version 2.38.2 and later. Users should upgrade to version 2.38.2 or newer to mitigate this vulnerability. Deployments using the default proxy pipeline with account-level TempURL keys are affected and should apply the update. No other specific mitigations are indicated.
CVE-2026-97149: CWE-184 Incomplete List of Disallowed Inputs in OpenStack Swift
Description
In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, and path, and thus the list of disallowed headers is the only defense against a signed PUT request changing what the request does. An attacker holding a PUT TempURL for a single object can add an X-Copy-From header naming any object in the same account; the copy middleware copies that object to the destination, and the attacker then reads the victim's data back with a GET TempURL for the destination object. Copies across account boundaries are rejected. Only deployments using the shipped default proxy pipeline (tempurl and copy middleware) with account-level TempURL keys are affected.
CVSS v4.0
Score 5.3medium
Affected software
OpenStack
Swift
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In OpenStack Swift versions before 2.38.2, the tempurl middleware fails to reject the X-Copy-From header on PUT requests. TempURL signatures protect only the HTTP method, expiry, and path, relying on a list of disallowed headers to prevent unauthorized request modifications. An attacker possessing a PUT TempURL for one object can add an X-Copy-From header referencing any other object in the same account, causing the copy middleware to duplicate that object to the destination. The attacker can then retrieve the copied data using a GET TempURL for the destination object. This vulnerability affects only deployments using the default proxy pipeline with account-level TempURL keys and does not allow copying across account boundaries.
Potential Impact
An attacker with a valid PUT TempURL for a single object can exploit this vulnerability to copy any object within the same account, potentially exposing sensitive data. The attacker can then read the copied data using a GET TempURL. This bypasses the intended security controls of TempURL signatures, leading to unauthorized data access within the same account. Cross-account data access is not possible, limiting the impact to objects within the attacker's account.
Mitigation Recommendations
A fix is available in OpenStack Swift version 2.38.2 and later. Users should upgrade to version 2.38.2 or newer to mitigate this vulnerability. Deployments using the default proxy pipeline with account-level TempURL keys are affected and should apply the update. No other specific mitigations are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-09-24T02:25:48.652Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab4bd46f7a7c54106ee9fef
Added to database: 09/24/2026, 06:03:50 UTC
Last enriched: 09/24/2026, 06:11:28 UTC
Last updated: 09/25/2026, 03:58:51 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.