HIGH7.4PyPI
GHSA-mm7j-mhhj-hj36· CVE-2026-40213, PYSEC-2026-2853OpenStack Cyborg uses rule:allow (check_str='@') as the default policy for multiple API endpoints
Modified: 7/13/2026
package
pkg:pypi/openstack-cyborg
OpenStack Cyborg uses rule:allow (check_str='@') as the default policy for multiple API endpoints
Modified: 7/13/2026
OpenStack Cyborg's Accelerator Request (ARQ) API does not enforce project ownership at any layer
Modified: 7/13/2026
OpenStack Cyborg uses rule:allow (check_str='@') as the default policy for multiple API endpoints
Modified: 7/13/2026
OpenStack Cyborg's Accelerator Request (ARQ) API does not enforce project ownership at any layer
Modified: 7/13/2026