VDB
Sign up
—

PYSEC-2026-879

OpenStack Nova Denial of Service in network source security groups

Quick fix

PYSEC-2026-879 — nova: upgrade to the fixed version with the command below.

pip install --upgrade 'nova>=12.0.0a0'

Details

Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security group policy updates, which allows remote authenticated users to cause a denial of service (nova-network consumption) via a large number of server-creation operations, which triggers a large number of update requests.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/nova
Introduced in: 0Fixed in: 12.0.0a0
Fixpip install --upgrade 'nova>=12.0.0a0'

References