OpenStack Zaqar WebSocket flaw allows cross-project queue access
OpenStack disclosed a Zaqar WebSocket project-substitution bug that can access another project's queues; sources disagree on versions.
OpenStack advisory OSSA-2026-043 discloses a Zaqar WebSocket project-substitution flaw that can let a user access queues belonging to another project. The initial notice, coordinated through the OpenStack security process and credited to reporter Chen YuXiang, said a CVE was still pending. Later the same day, errata 1 assigned CVE-2026-107363 and said exploitation had not been reported. The sources disagree on scope: the first notice lists Zaqar 1.0.0 through 22.0.0, 21.0.0 through 22.0.2, and 23.0.0, with fixes in 22.0.3 and 23.0.1, while errata 1 says versions from 1.0.0 before 20.1.3 are affected.
- OSSA-2026-043 describes an OpenStack Zaqar WebSocket project-substitution flaw that can allow access to another project's queues.
- The first notice said a CVE was pending; errata 1 later the same day assigned CVE-2026-107363.
- Reporter Chen YuXiang's disclosure was coordinated through the OpenStack security process.
- The initial notice lists affected Zaqar releases as 1.0.0 through 22.0.0, 21.0.0 through 22.0.2, and 23.0.0, with fixes in 22.0.3 and 23.0.1.
- Errata 1 instead says affected releases are Zaqar 1.0.0 up to, but not including, 20.1.3.
- Errata 1 does not report exploitation.
Coverage timelineoldest first · each row is one article
- · 1d ago[OSSA-2026-043] OpenStack Zaqar: Zaqar WebSocket project substitution allows cross-project queue access (CVE-2026-pending)
oss-security· 45
OpenStack Zaqar WebSocket project substitution flaw permits cross-project queue access across multiple releases, fixed in 22.0.3 and 23.0.1.
- · 1d agoRe: [OSSA-2026-043] OpenStack Zaqar: Zaqar WebSocket project substitution allows cross-project queue access (CVE-2026-107363) errata 1
oss-security· 52
OpenStack assigned CVE-2026-107363 to a Zaqar WebSocket flaw enabling cross-project queue access.
Vulnerabilities in this storyAll →
- CVE-2026-1073636.1—Cross-project queue access in OpenStack Zaqar WebSocketpublished · OpenStack Zaqar
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-107363 | Cross-project queue access in OpenStack Zaqar WebSocket OpenStack Zaqar before 23.0.1 fails, on its WebSocket transport, to bind later requests to the project authenticated by the Keystone token. An authenticated user who already holds a valid token for one project can substitute another project's UUID and then enumerate, inspect, create, or delete that project's queues, which can disclose, modify, or destroy queue data. Only deployments that use the WebSocket transport together with Keystone authentication are affected. No public proof-of-concept is known, the issue is not in CISA KEV, and the related notice is the OpenStack advisory OSSA-2026-043. Do: Upgrade OpenStack Zaqar to 23.0.1 or later. Until that is done, disable the WebSocket transport (or stop using it with Keystone) and review access logs for requests whose project UUID does not match the project bound to the Keystone token. Confirm the deployment actually uses WebSocket with Keystone before treating this as in scope; other transports are not described as affected. |