Heat: OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone…
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.
AI Analysis
Technical Summary
This vulnerability in OpenStack Keystone prior to versions 26.0.1, 27.0.0, and 28.0.0 allows an attacker to use a valid AWS Signature in requests to the /v3/ec2tokens or /v3/s3tokens endpoints to obtain Keystone authorization improperly. The issue impacts the Heat project across many specific Ubuntu package versions. The vulnerability is identified by CVSS vector AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N, indicating network attack vector, high attack complexity, no privileges or user interaction required, with a scope change, low confidentiality impact, high integrity impact, and no availability impact.
Potential Impact
An attacker with a valid AWS Signature can gain unauthorized Keystone authorization via the vulnerable endpoints, potentially allowing them to escalate privileges or perform unauthorized actions within the OpenStack environment. The vulnerability affects confidentiality and integrity but does not impact availability. There are no known exploits in the wild as of the published date.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Users should monitor vendor advisories for updates and apply official patches once available. Until then, restrict access to the vulnerable endpoints and validate AWS Signature usage carefully.
Heat: OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone…
Description
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.
CVSS v3.1
Score 7.5high
Affected software
pkg:deb/ubuntu/heat@1:6.1.2-0ubuntu1.1?arch=source&distro=xenialpkg:deb/ubuntu/keystone@2:9.3.0-0ubuntu3.2?arch=source&distro=xenialpkg:deb/ubuntu/[email protected]?arch=source&distro=xenialpkg:deb/ubuntu/heat@1:10.0.2-0ubuntu1.1?arch=source&distro=bionicpkg:deb/ubuntu/keystone@2:13.0.4-0ubuntu1?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/heat@1:14.2.0-0ubuntu2?arch=source&distro=focalpkg:deb/ubuntu/keystone@2:17.0.1-0ubuntu2+esm1?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/heat@1:18.0.1-0ubuntu1.4?arch=source&distro=jammypkg:deb/ubuntu/keystone@2:21.0.1-0ubuntu2.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/heat@1:22.0.1-0ubuntu1.3?arch=source&distro=noblepkg:deb/ubuntu/keystone@2:25.0.0-0ubuntu1.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/heat@1:25.0.0-0ubuntu1?arch=source&distro=questingpkg:deb/ubuntu/keystone@2:28.0.0-0ubuntu1.1?arch=source&distro=questingpkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/heat@1:26.0.0-0ubuntu1.1?arch=source&distro=resolutepkg:deb/ubuntu/keystone@2:28.0.0-0ubuntu2?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in OpenStack Keystone prior to versions 26.0.1, 27.0.0, and 28.0.0 allows an attacker to use a valid AWS Signature in requests to the /v3/ec2tokens or /v3/s3tokens endpoints to obtain Keystone authorization improperly. The issue impacts the Heat project across many specific Ubuntu package versions. The vulnerability is identified by CVSS vector AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N, indicating network attack vector, high attack complexity, no privileges or user interaction required, with a scope change, low confidentiality impact, high integrity impact, and no availability impact.
Potential Impact
An attacker with a valid AWS Signature can gain unauthorized Keystone authorization via the vulnerable endpoints, potentially allowing them to escalate privileges or perform unauthorized actions within the OpenStack environment. The vulnerability affects confidentiality and integrity but does not impact availability. There are no known exploits in the wild as of the published date.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Users should monitor vendor advisories for updates and apply official patches once available. Until then, restrict access to the vulnerable endpoints and validate AWS Signature usage carefully.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2025-65073
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6a6151239c2644c7f8da6236
Added to database: 07/22/2026, 23:24:19 UTC
Last enriched: 07/23/2026, 13:43:07 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 48
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.