{"id":"CVE-2026-94572","details":"In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the amphora, and thus an authenticated project member who owns a TLS-enabled load balancer can embed a newline and inject arbitrary HAProxy configuration directives. Only deployments using the Amphora provider are affected.","modified":"2026-09-22T11:46:09.240760599Z","published":"2026-09-21T20:13:35.557Z","database_specific":{"cna_assigner":"mitre","cwe_ids":["CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94572.json","unresolved_ranges":[{"extracted_events":[{"introduced":"17.0.0"},{"fixed":"17.0.1"},{"introduced":"18.0.0"},{"fixed":"18.0.1"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"REPORT","url":"https://bugs.debian.org/1148175"},{"type":"REPORT","url":"https://bugs.launchpad.net/octavia/+bug/2162101"},{"type":"REPORT","url":"https://bugs.launchpad.net/octavia/+bug/2167565"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94572.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94572"},{"type":"WEB","url":"https://opendev.org/openstack/octavia"},{"type":"FIX","url":"https://opendev.org/openstack/octavia/commit/cad62902e4984a46ad80cbfa943e90006d8d599d"},{"type":"ARTICLE","url":"https://openwall.com/lists/oss-security/2026/09/21/6"},{"type":"ADVISORY","url":"https://security.openstack.org/ossa/OSSA-2026-039.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://opendev.org/openstack/octavia","events":[{"introduced":"0f0e594e179091e1632cb0f80849bb5f8a6b4158"},{"fixed":"9994bc7d4bc51771fd24384f8e5edb480063d929"}],"database_specific":{"extracted_events":[{"introduced":"6.0.0"},{"fixed":"16.1.0"}],"source":"AFFECTED_FIELD"}}],"versions":["16.0.1","16.0.0.0rc2","16.0.0","16.0.0.0rc1","15.0.0.0rc1","15.0.0","14.0.0.0rc1","14.0.0","13.0.0.0rc1","13.0.0","12.0.0.0rc1","11.0.0.0rc1","11.0.0","10.0.0.0rc1","10.0.0","9.0.0.0rc1","9.0.0","8.0.0.0rc1","7.0.0.0rc1","7.0.0","6.0.0.0rc1","6.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94572.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}