VDB
Sign up
MEDIUM6.5

PYSEC-2026-650

OpenStack Keystone Denial of Service vulnerability via a large HTTP request

Quick fix

PYSEC-2026-650 — keystone: upgrade to the fixed version with the command below.

pip install --upgrade 'keystone>=8.0.0a0'

Details

OpenStack Keystone Grizzly before 2013.1, Folsom, and possibly earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a large HTTP request, as demonstrated by a long tenant_name when requesting a token.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/keystone
Introduced in: 0Fixed in: 8.0.0a0
Fixpip install --upgrade 'keystone>=8.0.0a0'

References