[OSSA-2026-042] OpenStack Zaqar: Zaqar empty URL-Signature header bypasses authentication (CVE-2026-97404)
OpenStack Zaqar advisory CVE-2026-97404: an empty URL-Signature header can bypass authentication.
OpenStack Security Advisory OSSA-2026-042 discloses CVE-2026-97404 in the Zaqar messaging service. An empty URL-Signature header can bypass authentication. An independent security researcher reported the flaw, and the notice lists affected Zaqar releases with 22.0.2 as a fix boundary. The advisory does not say the bug is being exploited.