MEDIUM6.0
PYSEC-2026-1214
OpenStack Barbican information disclosure vulnerability
Details
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/barbican
Introduced in:
0No fixed version published yet for barbican (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-1636[ADVISORY]
- https://access.redhat.com/security/cve/CVE-2023-1636[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2181765[WEB]
- https://github.com/openstack/barbican[PACKAGE]
- https://pypi.org/project/barbican[PACKAGE]
- https://github.com/advisories/GHSA-6rx9-c2rh-3qv4[ADVISORY]