CVE-2026-71190

OpenStack · Swift

OpenStack Swift contains an inefficient regular expression complexity vulnerability that can be exploited by unauthenticated remote attackers to cause a denial of service.

Executive summary

OpenStack Swift is vulnerable to a denial of service attack via inefficient regular expression complexity, which may lead to significant system resource exhaustion.

Vulnerability

The software is susceptible to CWE-1333, which involves inefficient regular expression complexity. An unauthenticated remote attacker can supply specifically crafted input to trigger high CPU consumption, resulting in a denial of service condition.

Business impact

Exploitation of this vulnerability leads to service unavailability, which can severely impact business operations that rely on the Swift object storage service. With a CVSS score of 8.7, this vulnerability poses a high risk to service continuity and platform stability.

Remediation

Immediate Action: Upgrade to the patched versions (2.35.4, 2.36.3, 2.37.3, or later as applicable) provided by the OpenStack project.

Proactive Monitoring: Monitor resource utilization, specifically CPU spikes on Swift nodes, which may indicate an ongoing denial of service attempt.

Compensating Controls: Deploy a Web Application Firewall or rate-limiting middleware to inspect and filter incoming requests for patterns that match known complex regular expression attacks.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for service disruption, organizations should schedule and apply the necessary patches as soon as possible. Maintaining service uptime is critical, and this update is essential for protecting the availability of OpenStack Swift.