{"id":"DEBIAN-CVE-2026-97149","details":"In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, and path, and thus the list of disallowed headers is the only defense against a signed PUT request changing what the request does. An attacker holding a PUT TempURL for a single object can add an X-Copy-From header naming any object in the same account; the copy middleware copies that object to the destination, and the attacker then reads the victim's data back with a GET TempURL for the destination object. Copies across account boundaries are rejected. Only deployments using the shipped default proxy pipeline (tempurl and copy middleware) with account-level TempURL keys are affected.","modified":"2026-09-26T11:00:07.494059953Z","published":"2026-09-24T03:16:59.133Z","upstream":["CVE-2026-97149"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-97149"}],"affected":[{"package":{"name":"swift","ecosystem":"Debian:12","purl":"pkg:deb/debian/swift?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.30.0-4","2.30.1-0+deb12u1","2.30.1-0+deb12u2","2.31.0-1","2.31.1-1","2.31.1-3","2.31.1-4","2.32.0-1","2.32.0-2","2.32.0-3","2.33.0-1","2.33.0-2","2.33.0-3","2.33.0-4","2.33.0-5","2.33.0-6","2.33.0-7","2.34.0-1","2.34.0-2","2.34.0-3","2.34.0-4","2.34.0-5","2.35.0-1","2.35.0-2","2.35.0-3","2.35.0-4","2.35.1-1","2.35.1-2","2.36.0-1","2.36.0-2","2.36.0-3","2.36.0-4","2.36.0-5","2.36.0-6","2.36.0-7","2.36.0-8","2.37.0-1","2.37.1-1","2.37.1-2","2.37.1-3","2.37.1-4","2.37.1-5","2.37.1-6","2.38.1-1","2.38.1-2","2.38.1-3"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-97149.json"}},{"package":{"name":"swift","ecosystem":"Debian:13","purl":"pkg:deb/debian/swift?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.35.0-4","2.35.1-0+deb13u1","2.35.1-0+deb13u2","2.35.1-0+deb13u3","2.35.1-1","2.35.1-2","2.36.0-1","2.36.0-2","2.36.0-3","2.36.0-4","2.36.0-5","2.36.0-6","2.36.0-7","2.36.0-8","2.37.0-1","2.37.1-1","2.37.1-2","2.37.1-3","2.37.1-4","2.37.1-5","2.37.1-6","2.38.1-1","2.38.1-2","2.38.1-3"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-97149.json"}},{"package":{"name":"swift","ecosystem":"Debian:14","purl":"pkg:deb/debian/swift?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.38.1-3"}]}],"versions":["2.35.0-4","2.35.1-1","2.35.1-2","2.36.0-1","2.36.0-2","2.36.0-3","2.36.0-4","2.36.0-5","2.36.0-6","2.36.0-7","2.36.0-8","2.37.0-1","2.37.1-1","2.37.1-2","2.37.1-3","2.37.1-4","2.37.1-5","2.37.1-6","2.38.1-1","2.38.1-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-97149.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}