[OSSA-2026-043] OpenStack Zaqar: Zaqar WebSocket project substitution allows cross-project queue access (CVE-2026-pending)
OpenStack Zaqar WebSocket project substitution flaw permits cross-project queue access across multiple releases, fixed in 22.0.3 and 23.0.1.
OSSA-2026-043 discloses a vulnerability in OpenStack Zaqar where WebSocket project substitution allows cross-project queue access. The flaw affects Zaqar versions 1.0.0 through 22.0.0, 21.0.0 through 22.0.2, and 23.0.0, with fixes available in 22.0.3 and 23.0.1. Reporter Chen YuXiang's disclosure was coordinated through the OpenStack security process. A CVE identifier is pending assignment.
- WebSocket project substitution enables cross-project queue access in Zaqar
- Affects Zaqar releases from 1.0.0 through 23.0.0
- Patched in Zaqar 22.0.3 and 23.0.1
- CVE identifier still pending at disclosure time
Posted by Goutham Pacha Ravi on Oct 07 ===================================================================================== OSSA-2026-043: Zaqar WebSocket project substitution allows cross-project queue access ===================================================================================== :Date: October 07, 2026 :CVE: CVE-2026-pending Affects ~~~~~~~ - Zaqar: >=1.0.0 =21.0.0 =22.0.0 <22.0.3, ==23.0.0 Description ~~~~~~~~~~~ Chen YuXiang...
This source does not provide full text. Read it at seclists.org.