USN-8814-1: Octavia vulnerabilities
Ubuntu patches multiple OpenStack Octavia flaws allowing authenticated load-balancer owners to inject arbitrary HAProxy configuration directives.
Ubuntu Security Notice USN-8814-1 fixes several vulnerabilities in OpenStack Octavia. CVE-2026-94572 stems from improper validation of TLS cipher string fields in the Amphora provider driver, and CVE-2026-94571 from improper validation of L7 policy redirect URL fields; both allow an authenticated attacker who owns a load balancer to inject arbitrary HAProxy configuration directives. A third flaw involves incorrect quality of service policy authorization handling by authenticated attackers. No exploitation is mentioned in the notice.
- Octavia Amphora driver fails to validate TLS cipher and L7 redirect URL fields
- Authenticated load-balancer owners can inject arbitrary HAProxy configuration directives
- QoS policy authorization also handled incorrectly
- Fixed via Ubuntu security notice USN-8814-1
Vulnerabilities mentionedAll →
- CVE-2026-945719.4—HAProxy Config Injection via L7 Policy Redirect Fields in OpenStack Octaviapublished · Open Infrastructure Foundation (OpenStack) OpenStack Octavia (Amphora provider driver)
- CVE-2026-945729.4—HAProxy Config Injection in OpenStack Octavia Amphora Driver via tls_cipherspublished · OpenStack Octavia (Amphora provider driver)
| CVE | Vulnerability |
|---|
It was discovered that Octavia did not properly validate TLS cipher string fields in the Amphora provider driver. An authenticated attacker who owns a TLS-enabled load balancer could possibly use this issue to inject arbitrary HAProxy configuration directives. (CVE-2026-94572) It was discovered that Octavia did not properly validate L7 policy redirect URL fields in the Amphora provider driver. An authenticated attacker who owns a load balancer could possibly use this issue to inject arbitrary HAProxy configuration directives. (CVE-2026-94571) It was discovered that Octavia incorrectly handled quality of service policy authorization. An authenticated attacker could possibly use this issue to…
This source does not provide full text. Read it at ubuntu.com.