[OSSA-2026-039] OpenStack Octavia: HAProxy configuration injection leading to remote code execution in Octavia (CVE-2026-94572, CVE-2026-94571)
OpenStack Octavia advisory warns HAProxy config injection can lead to remote code execution.
OpenStack published OSSA-2026-039, dated 21 September 2026, warning that HAProxy configuration injection in Octavia can lead to remote code execution. The issue is tracked as CVE-2026-94572 and CVE-2026-94571. Affected versions are Octavia 0.8.0 through releases before 16.1.0, as well as 17.0.0 and 18.0.0. The published excerpt does not say the flaw is being exploited.