OpenStack Octavia

2 known vulnerabilities in OpenStack Octavia, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-94572 CVSS 9.4 critical In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control…
  • CVE-2026-94571 CVSS 9.4 critical In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and…