Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97149

Quick assessment

Affected
OpenStack Swift
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 OpenStack Swift 2.38.2 之前的版本中,tempurl 中间件未在 PUT 请求中拒绝 X-Copy-From 头部字段。TempURL 签名仅涵盖方法、过期时间和路径,因此防止签名 PUT 请求改变请求行为的唯一防御机制是黑名单式的不允许头部列表。持有单个对象 PUT TempURL 的攻击者可以添加一个 X-Copy-From 头部,指向同一账户中的任意其他对象;copy 中间件会将该对象复制到目标位置,随后攻击者通过目标对象的 GET TempURL 读取受害者的数据。跨账户边界的复制

CVSS 5.3 · Medium EPSS 0.24% · P13
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97149

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, and path, and thus the list of disallowed headers is the only defense against a signed PUT request changing what the request does. An attacker holding a PUT TempURL for a single object can add an X-Copy-From header naming any object in the same account; the copy middleware copies that object to the destination, and the attacker then reads the victim's data back with a GET TempURL for the destination object. Copies across account boundaries are rejected. Only deployments using the shipped default proxy pipeline (tempurl and copy middleware) with account-level TempURL keys are affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
不完整的黑名单
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OpenStack Swift 2.4.0 ~ 2.35.5 -

II. Public POCs for CVE-2026-97149

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97149

请登录查看更多情报信息。

Other References for CVE-2026-97149 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-97149

No comments yet


Leave a comment