GHSA-xwpf-r3rp-gx2rCritical

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and...

Published
September 21, 2026
Last Modified
September 21, 2026

🔗 CVE IDs covered (1)

📋 Description

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the amphora, and thus an authenticated project member who owns a TLS-enabled load balancer can embed a newline and inject arbitrary HAProxy configuration directives. Only deployments using the Amphora provider are affected.

🔗 References (8)