AI analysis
OpenStack Zaqar before 23.0.1 fails, on its WebSocket transport, to bind later requests to the project authenticated by the Keystone token. An authenticated user who already holds a valid token for one project can substitute another project's UUID and then enumerate, inspect, create, or delete that project's queues, which can disclose, modify, or destroy queue data. Only deployments that use the WebSocket transport together with Keystone authentication are affected. No public proof-of-concept is known, the issue is not in CISA KEV, and the related notice is the OpenStack advisory OSSA-2026-043.
What to do: Upgrade OpenStack Zaqar to 23.0.1 or later. Until that is done, disable the WebSocket transport (or stop using it with Keystone) and review access logs for requests whose project UUID does not match the project bound to the Keystone token. Confirm the deployment actually uses WebSocket with Keystone before treating this as in scope; other transports are not described as affected.
Affected
| OpenStack Zaqar | before 23.0.1 |
Estimated exposure
nicheNo basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the project identifier in subsequent requests to the project authenticated by the Keystone token. An authenticated user with a valid token for one project may substitute another project's UUID to enumerate, inspect, create, or delete queues belonging to that project, resulting in unauthorized disclosure, modification, or loss of queue data. Only deployments using the WebSocket transport with Keystone authentication are affected.