[OSSA-2026-042] OpenStack Zaqar: Zaqar empty URL-Signature header bypasses authentication (CVE-2026-97404)
OpenStack Zaqar advisory CVE-2026-97404: an empty URL-Signature header can bypass authentication.
OpenStack Security Advisory OSSA-2026-042 discloses CVE-2026-97404 in the Zaqar messaging service. An empty URL-Signature header can bypass authentication. An independent security researcher reported the flaw, and the notice lists affected Zaqar releases with 22.0.2 as a fix boundary. The advisory does not say the bug is being exploited.
- Empty URL-Signature header bypasses Zaqar authentication
- Tracked as CVE-2026-97404 and OSSA-2026-042
- Independent researcher reported the authentication flaw
- Advisory does not report active exploitation
Vulnerabilities mentionedAll →
- CVE-2026-974049.2—Auth Bypass via Empty URL-Signature Header in OpenStack Zaqar WSGI Transportpublished · OpenStack Zaqar (WSGI transport with an authentication strategy configured)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-97404 | Auth Bypass via Empty URL-Signature Header in OpenStack Zaqar WSGI Transport OpenStack Zaqar before 22.0.2 mishandles the URL-Signature header in its WSGI transport, so a request carrying an empty URL-Signature value bypasses both Keystone authentication and pre-signed URL verification. An unauthenticated remote attacker who knows a target project's UUID can exploit this to read, enumerate, create, and delete that project's queues, messages, claims, and subscriptions; by additionally claiming an administrative role, the attacker can also perform admin operations such as managing pools and flavors in admin_mode deployments. Only deployments using the WSGI transport with an authentication strategy configured are affected; the websocket transport is not. The flaw is rated critical (CVSS 4.0: 9.2), but successful exploitation requires prior knowledge of a victim project's UUID, which limits purely opportunistic attacks. No public PoC exists, there is no evidence of exploitation in the wild, and the CVE is not on CISA's KEV list. |
Posted by Goutham Pacha Ravi on Sep 24 ======================================================================= OSSA-2026-042: Zaqar empty URL-Signature header bypasses authentication ======================================================================= :Date: September 24, 2026 :CVE: CVE-2026-97404 Affects ~~~~~~~ - Zaqar: >=1.0.0 =21.0.0 =22.0.0 <22.0.2 Description ~~~~~~~~~~~ pple, an independent security researcher, reported that...
This source does not provide full text. Read it at seclists.org.