VDB
Sign up
MEDIUM6.1

PYSEC-2026-693

Open Redirect in CPython that affects users of OpenStack Nova

Quick fix

PYSEC-2026-693 — nova: upgrade to the fixed version with the command below.

pip install --upgrade 'nova>=21.2.3'

Details

A vulnerability was found in CPython which is used by openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/nova
Introduced in: 0Fixed in: 21.2.3
Fixpip install --upgrade 'nova>=21.2.3'

References