CVE Database
/

CVE-2026-49017

Back to search

CVE-2026-49017

Published: May 27, 2026

Modified: Jun 2, 2026

PUBLISHED

Description

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0.

VendorProductVersions

OpenStack

Swift

affected
2.36.0 - < 2.36.2
affected
2.37.0 - < 2.37.2
affected
2.35.1 - < 2.35.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now