{"id":"DEBIAN-CVE-2026-46448","details":"In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.","modified":"2026-09-14T17:03:16.407692589Z","published":"2026-06-16T20:16:41.697Z","upstream":["CVE-2026-46448"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-46448"}],"affected":[{"package":{"name":"nova","ecosystem":"Debian:12","purl":"pkg:deb/debian/nova?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2:26.1.0-4","2:26.2.2-1~deb12u3","2:26.2.2-1~deb12u4","2:27.0.0-1","2:27.0.0-2","2:27.0.0-3","2:27.0.0-4","2:27.0.0-5","2:27.0.0-6","2:27.0.0~rc1-1","2:28.0.0-1","2:28.0.0-2","2:28.0.0~rc1-1","2:29.0.0~rc1-1","2:29.0.1-1","2:29.0.1-2","2:29.0.1-3","2:29.0.1-4","2:29.0.1-5","2:29.0.1-6","2:29.0.2-1","2:29.0.2-2","2:29.0.2-4","2:30.0.0-1","2:30.0.0-2","2:30.0.0-3","2:30.0.0-4","2:30.0.0-5","2:30.0.0-6","2:30.0.0-7","2:30.0.0-8","2:30.0.0~rc1-1","2:31.0.0-1","2:31.0.0-2","2:31.0.0-3","2:31.0.0-4","2:31.0.0-5","2:31.0.0-6","2:31.0.0-7","2:31.0.0~rc1-1","2:31.0.0~rc1-2","2:32.0.0-1","2:32.0.0~rc1-1","2:32.0.0~rc1-2","2:32.0.0~rc1-3","2:32.1.0-1","2:32.1.0-2","2:32.1.0-3","2:32.1.0-4","2:32.1.0-5","2:32.1.0-6","2:32.1.0-7","2:33.0.0-1","2:33.0.0-2","2:33.0.0-3","2:33.0.0-4","2:33.0.0~rc1-1","2:33.0.0~rc1-2","2:33.0.0~rc1-3","2:33.0.0~rc1-4","2:33.0.0~rc1-5","2:33.0.1-1","2:33.0.1-2","2:33.0.1-4","2:33.0.1-5","2:33.0.2-1","2:34.0.0~rc1-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46448.json"}},{"package":{"name":"nova","ecosystem":"Debian:13","purl":"pkg:deb/debian/nova?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2:31.0.0-6","2:31.0.0-6+deb13u1","2:31.0.0-6+deb13u2","2:31.0.0-7","2:32.0.0-1","2:32.0.0~rc1-1","2:32.0.0~rc1-2","2:32.0.0~rc1-3","2:32.1.0-1","2:32.1.0-2","2:32.1.0-3","2:32.1.0-4","2:32.1.0-5","2:32.1.0-6","2:32.1.0-7","2:33.0.0-1","2:33.0.0-2","2:33.0.0-3","2:33.0.0-4","2:33.0.0~rc1-1","2:33.0.0~rc1-2","2:33.0.0~rc1-3","2:33.0.0~rc1-4","2:33.0.0~rc1-5","2:33.0.1-1","2:33.0.1-2","2:33.0.1-4","2:33.0.1-5","2:33.0.2-1","2:34.0.0~rc1-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46448.json"}},{"package":{"name":"nova","ecosystem":"Debian:14","purl":"pkg:deb/debian/nova?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:33.0.1-4"}]}],"versions":["2:31.0.0-6","2:31.0.0-7","2:32.0.0-1","2:32.0.0~rc1-1","2:32.0.0~rc1-2","2:32.0.0~rc1-3","2:32.1.0-1","2:32.1.0-2","2:32.1.0-3","2:32.1.0-4","2:32.1.0-5","2:32.1.0-6","2:32.1.0-7","2:33.0.0-1","2:33.0.0-2","2:33.0.0-3","2:33.0.0-4","2:33.0.0~rc1-1","2:33.0.0~rc1-2","2:33.0.0~rc1-3","2:33.0.0~rc1-4","2:33.0.0~rc1-5","2:33.0.1-1","2:33.0.1-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46448.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H"}]}