Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-94572: OpenStack Octavia allows load‑balancer config injection

CVE-2026-94572 · published today
Summary

The Octavia component that creates load balancers can accept special characters in TLS settings without checking them. An attacker who controls a TLS‑enabled load balancer could insert new lines and change the HAProxy configuration, potentially altering traffic handling. Update Octavia to version 18.0.1 or later, or apply the provided patch, to enforce proper validation.

What to do
  • Update openstack octavia to version 16.1.0 or later.
Affected software
VendorProductAffected versions
openstack octavia < 16.1.0
Original advisory text
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy confi...
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the amphora, and thus an authenticated project member who owns a TLS-enabled load balancer can embed a newline and inject arbitrary HAProxy configuration directives. Only deployments using the Amphora provider are affected.
Severity
9.4 Critical
Type
CWE-94Code Injection
Timeline
Published21 Sep 2026
Updated21 Sep 2026
First seen21 Sep 2026
Sources
CVE-2026-94572 · MITRE
Track software like this
Free during beta