Source: horizon
Version: 3:25.7.2-1
Severity: important
Tags: security upstream
Forwarded: https://review.opendev.org/c/openstack/horizon/+/986834
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for horizon.

CVE-2026-43002[0]:
| An issue was discovered in OpenStack Horizon 25.6 and 25.7 before
| 25.7.3. There is a write operation to the session storage backend
| before authentication and thus storage can be exhausted by
| unauthenticated requests. This is a regression of the CVE-2014-8124
| fix.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-43002
    https://www.cve.org/CVERecord?id=CVE-2026-43002
[1] https://review.opendev.org/c/openstack/horizon/+/98683

Regards,
Salvatore

Reply via email to