Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6314-1 | swift security update |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 27 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 27 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0. | |
| First Time appeared |
Openstack
Openstack swift |
|
| Weaknesses | CWE-835 | |
| CPEs | cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack swift |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-02T17:33:08.620Z
Reserved: 2026-05-27T01:57:58.189Z
Link: CVE-2026-49017
Updated: 2026-06-02T17:33:08.620Z
Status : Awaiting Analysis
Published: 2026-05-27T02:16:34.327
Modified: 2026-06-17T10:55:27.240
Link: CVE-2026-49017
No data.
OpenCVE Enrichment
Updated: 2026-05-27T03:30:06Z
Debian DSA