In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, and path, and thus the list of disallowed headers is the only defense against a signed PUT request changing what the request does. An attacker holding a PUT TempURL for a single object can add an X-Copy-From header naming any object in the same account; the copy middleware copies that object to the destination, and the attacker then reads the victim's data back with a GET TempURL for the destination object. Copies across account boundaries are rejected. Only deployments using the shipped default proxy pipeline (tempurl and copy middleware) with account-level TempURL keys are affected.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://launchpad.net/bugs/2166876 |
|
History
Thu, 24 Sep 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Swift TempURL Exploit Enables Unauthorized Copy via X‑Copy‑From Header |
Thu, 24 Sep 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, and path, and thus the list of disallowed headers is the only defense against a signed PUT request changing what the request does. An attacker holding a PUT TempURL for a single object can add an X-Copy-From header naming any object in the same account; the copy middleware copies that object to the destination, and the attacker then reads the victim's data back with a GET TempURL for the destination object. Copies across account boundaries are rejected. Only deployments using the shipped default proxy pipeline (tempurl and copy middleware) with account-level TempURL keys are affected. | |
| First Time appeared |
Openstack
Openstack swift |
|
| Weaknesses | CWE-184 | |
| CPEs | cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack swift |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-24T02:25:49.093Z
Reserved: 2026-09-24T02:25:48.652Z
Link: CVE-2026-97149
No data.
Status : Received
Published: 2026-09-24T03:16:59.133
Modified: 2026-09-24T03:16:59.133
Link: CVE-2026-97149
No data.
OpenCVE Enrichment
Updated: 2026-09-24T03:30:08Z
Weaknesses