Description
In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The "qdtext" pattern (?:[^"]|\\.)* allows an unauthenticated remote attacker to send a crafted Accept header that causes exponential CPU consumption in the proxy worker. A payload of 32 backslash-character pairs exceeds 30 seconds of CPU time. No authentication is required. Repeated requests can exhaust all proxy worker threads, resulting in a complete denial of service.
Published: 2026-08-05
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title OpenStack Swift Accept Header Regular Expression ReDoS Enables Denial of Service openstack-swift: openstack-swift: Unauthenticated denial of service via catastrophic backtracking in Accept header parser
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Wed, 05 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title OpenStack Swift Accept Header Regular Expression ReDoS Enables Denial of Service

Wed, 05 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Description In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The "qdtext" pattern (?:[^"]|\\.)* allows an unauthenticated remote attacker to send a crafted Accept header that causes exponential CPU consumption in the proxy worker. A payload of 32 backslash-character pairs exceeds 30 seconds of CPU time. No authentication is required. Repeated requests can exhaust all proxy worker threads, resulting in a complete denial of service.
First Time appeared Openstack
Openstack swift
Weaknesses CWE-1333
CPEs cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:*
Vendors & Products Openstack
Openstack swift
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-06T13:09:17.168Z

Reserved: 2026-08-05T04:54:02.394Z

Link: CVE-2026-71190

cve-icon Vulnrichment

Updated: 2026-08-05T18:32:08.027Z

cve-icon NVD

Status : Received

Published: 2026-08-05T06:16:40.023

Modified: 2026-08-06T14:16:41.060

Link: CVE-2026-71190

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-28T15:00:00Z

Links: CVE-2026-71190 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T07:00:10Z

Weaknesses