[OSSA-2026-039] OpenStack Octavia: HAProxy configuration injection leading to remote code execution in Octavia (CVE-2026-94572, CVE-2026-94571)
OpenStack Octavia advisory warns HAProxy config injection can lead to remote code execution.
OpenStack published OSSA-2026-039, dated 21 September 2026, warning that HAProxy configuration injection in Octavia can lead to remote code execution. The issue is tracked as CVE-2026-94572 and CVE-2026-94571. Affected versions are Octavia 0.8.0 through releases before 16.1.0, as well as 17.0.0 and 18.0.0. The published excerpt does not say the flaw is being exploited.
- OSSA-2026-039 describes HAProxy configuration injection in Octavia.
- Successful injection can lead to remote code execution.
- Tracked as CVE-2026-94572 and CVE-2026-94571.
- Affects Octavia before 16.1.0, plus 17.0.0 and 18.0.0.
Vulnerabilities mentionedAll →
- CVE-2026-945719.4—HAProxy Config Injection via L7 Policy Redirect Fields in OpenStack Octaviapublished · Open Infrastructure Foundation (OpenStack) OpenStack Octavia (Amphora provider driver)
- CVE-2026-945729.4—HAProxy Config Injection in OpenStack Octavia Amphora Driver via tls_cipherspublished · OpenStack Octavia (Amphora provider driver)
| CVE | Vulnerability |
|---|
Posted by Goutham Pacha Ravi on Sep 22 ========================================================================================== OSSA-2026-039: HAProxy configuration injection leading to remote code execution in Octavia ========================================================================================== :Date: September 21, 2026 :CVE: CVE-2026-94572, CVE-2026-94571 Affects ~~~~~~~ - Octavia: >=0.8.0 <16.1.0, ==17.0.0, ==18.0.0 Description ~~~~~~~~~~~ Chen...
This source does not provide full text. Read it at seclists.org.