OpenStack Octavia HAProxy injection flaws assigned CVEs
Authenticated Octavia owners can inject HAProxy config; OpenStack says that can yield remote code execution, and Ubuntu has patched it.
OpenStack Security Advisory OSSA-2026-039, dated 21 September 2026, warns that HAProxy configuration injection in Octavia can lead to remote code execution. The same-day oss-security posting listed the issue as CVE-2026-pending; a 22 September revision assigned CVE-2026-94572 and CVE-2026-94571, affecting Octavia 0.8.0 through releases before 16.1.0 as well as 17.0.0 and 18.0.0, with no fixed versions stated for the 17 and 18 branches. Ubuntu Security Notice USN-8814-1 (24 September 2026) says CVE-2026-94572 stems from improper validation of TLS cipher string fields in the Amphora provider driver and CVE-2026-94571 from improper validation of L7 policy redirect URL fields, allowing an authenticated load-balancer owner to inject arbitrary HAProxy directives. Unlike the OpenStack advisory, Ubuntu does not explicitly describe remote code execution. USN-8814-1 also fixes a separate incorrect quality-of-service policy authorization flaw that the OpenStack postings do not mention, and none of the reports cite observed exploitation.
- OSSA-2026-039, dated 21 September 2026, describes HAProxy configuration injection in OpenStack Octavia that can lead to remote code execution.
- The 21 September posting listed the identifier as CVE-2026-pending; the 22 September revision assigned CVE-2026-94572 and CVE-2026-94571.
- Affected releases are Octavia 0.8.0 through versions before 16.1.0, plus 17.0.0 and 18.0.0; fixed versions for the 17.0.0 and 18.0.0 branches are not stated.
- Ubuntu attributes CVE-2026-94572 to improper validation of TLS cipher string fields in the Amphora provider driver.
- Ubuntu attributes CVE-2026-94571 to improper validation of L7 policy redirect URL fields.
- Both flaws let an authenticated load-balancer owner inject arbitrary HAProxy configuration directives.
- USN-8814-1 (24 September 2026) also fixes incorrect quality-of-service policy authorization handling; no CVE for that issue is given.
- None of the reports mention observed exploitation.
Coverage timelineoldest first · each row is one article
- · 5d ago[OSSA-2026-039] OpenStack Octavia: HAProxy configuration injection leading to remote code execution in Octavia (CVE-2026-pending)
oss-security· 64
OpenStack Octavia advisory warns HAProxy configuration injection can lead to remote code execution.
- · 4d ago[OSSA-2026-039] OpenStack Octavia: HAProxy configuration injection leading to remote code execution in Octavia (CVE-2026-94572, CVE-2026-94571)
oss-security· 67
OpenStack Octavia advisory warns HAProxy config injection can lead to remote code execution.
- · 2d agoUSN-8814-1: Octavia vulnerabilities
Ubuntu Security Notices· 26
Vulnerabilities in this storyAll →
- CVE-2026-945719.4—HAProxy Config Injection via L7 Policy Redirect Fields in OpenStack Octaviapublished · Open Infrastructure Foundation (OpenStack) OpenStack Octavia (Amphora provider driver)
- CVE-2026-945729.4—HAProxy Config Injection in OpenStack Octavia Amphora Driver via tls_cipherspublished · OpenStack Octavia (Amphora provider driver)
| CVE | Vulnerability |
|---|