[OSSA-2026-039] OpenStack Octavia: HAProxy configuration injection leading to remote code execution in Octavia (CVE-2026-pending)
OpenStack Octavia advisory warns HAProxy configuration injection can lead to remote code execution.
OpenStack Security Advisory OSSA-2026-039, dated 21 September 2026, describes HAProxy configuration injection that can lead to remote code execution in Octavia. Affected releases are Octavia 0.8.0 up to but not including 16.1.0, as well as 17.0.0 and 18.0.0. The notice lists the issue as CVE-2026-pending, and the posted text does not report observed exploitation.
- OSSA-2026-039 covers HAProxy configuration injection in Octavia.
- Described impact is remote code execution.
- Affects Octavia before 16.1.0 plus 17.0.0 and 18.0.0.
- Identifiers are listed only as CVE-2026-pending.
Posted by Goutham Pacha Ravi on Sep 21 ========================================================================================== OSSA-2026-039: HAProxy configuration injection leading to remote code execution in Octavia ========================================================================================== :Date: September 21, 2026 :CVE: CVE-2026-pending, CVE-2026-pending Affects ~~~~~~~ - Octavia: >=0.8.0 <16.1.0, ==17.0.0, ==18.0.0 Description ~~~~~~~~~~~ Chen...
This source does not provide full text. Read it at seclists.org.