In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encodes …
Info
Summary
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encodes control characters before validating, and thus newlines passed structural checks, but Octavia stored and wrote the raw unencoded value directly into the HAProxy configuration generated on the amphora. An authenticated project member who owns a load balancer can therefore inject arbitrary HAProxy dir…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://bugs.debian.org/1148175
- https://bugs.launchpad.net/octavia/+bug/2162103
- https://bugs.launchpad.net/octavia/+bug/2167565
- https://opendev.org/openstack/octavia/commit/bad7074621562d90a38be4639c1ab3e245f5bf39
- https://openwall.com/lists/oss-security/2026/09/21/6
- https://security.openstack.org/ossa/OSSA-2026-039.html
Timeline
- nvd_ingest NVD