CVE-2026-50221 Details
Description
In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update requests to an attacker-controlled server, enabling server-side request forgery. The SSRF requests expose internal cluster metadata including storage policy indexes, partition mappings, device names, and when at rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key. The attacker can also cause "ghost listings" in arbitrary containers via the shard-range redirect mechanism.
A server-side request forgery (SSRF) vulnerability has been identified in OpenStack Swift's proxy-server component, affecting versions 2.0.0 through 2.35.3, 2.36.0 prior to 2.36.2, and 2.37.0 prior to 2.37.2. The vulnerability allows authenticated users with write access to inject internal update headers into client requests. These headers are not stripped before the requests are forwarded to object servers, enabling the injection of malicious payloads that can be used to redirect container update requests to attacker-controlled servers. Exploitation of this vulnerability exposes internal cluster metadata, including storage policy indexes, partition mappings, device names, and, if container-level encryption is enabled, cipher text and initialization vectors for the encryption key. Additionally, the vulnerability can cause 'ghost listings' in containers through the shard-range redirect mechanism.
Users can upgrade to OpenStack Swift versions 2.37.2, 2.36.2, or 2.35.3 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/23/5 | CVE | Mailing ListPatchThird Party Advisory |
| https://launchpad.net/bugs/2150261 | [email protected] | ExploitIssue TrackingVendor Advisory |
| https://security.openstack.org/ossa/OSSA-2026-024.html | [email protected] | PatchVendor Advisory |
| https://www.openwall.com/lists/oss-security/2026/06/23/5 | [email protected] | Mailing ListPatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openstack swift | >= 2.0.0, < 2.35.3 >= 2.36.0, < 2.36.2 >= 2.37.0, < 2.37.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 29, 2026 | Initial Analysis | [email protected] |
| Jun 23, 2026 | New CVE Received | [email protected] |
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | CVE Modified | CVE |