OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-94571

CRITICAL · CVSS 9.4 EPSS 0.53%

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Amphora provider driver in OpenStack Octavia versions prior to 18.0.1 is vulnerable due to improper handling of control characters in the L7 policy redirect_url and redirect_prefix fields, allowing authenticated users to inject arbitrary HAProxy directives. This critical vulnerability can lead to significant security risks, including potential unauthorized access or manipulation of traffic. Organizations utilizing the Amphora provider should prioritize patching to mitigate these risks.

CVE
CVE-2026-94571
Severity
CRITICAL
CVSS
9.4
EPSS
0.53%

Original NVD Description

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encodes control characters before validating, and thus newlines passed structural checks, but Octavia stored and wrote the raw unencoded value directly into the HAProxy configuration generated on the amphora. An authenticated project member who owns a load balancer can therefore inject arbitrary HAProxy directives through a REDIRECT_TO_URL L7 policy. Only deployments using the Amphora provider are affected.