VDB
Sign up
MEDIUM5.3

PYSEC-2026-2520

OpenStack Horizon has Incorrect Behavior Order

Quick fix

PYSEC-2026-2520 — horizon: upgrade to the fixed version with the command below.

pip install --upgrade 'horizon>=25.7.3'

Details

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/horizon
Introduced in: 25.6Fixed in: 25.7.3
Fixpip install --upgrade 'horizon>=25.7.3'

References