{"id":"UBUNTU-CVE-2026-50221","details":"In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update requests to an attacker-controlled server, enabling server-side request forgery. The SSRF requests expose internal cluster metadata including storage policy indexes, partition mappings, device names, and when at rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key. The attacker can also cause \"ghost listings\" in arbitrary containers via the shard-range redirect mechanism.","modified":"2026-06-30T18:15:30.482455481Z","published":"2026-06-23T18:18:00Z","upstream":["CVE-2026-50221"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-50221"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-50221"},{"type":"REPORT","url":"https://www.openwall.com/lists/oss-security/2026/06/23/5"},{"type":"REPORT","url":"https://bugs.launchpad.net/swift/+bug/2150261"}],"affected":[{"package":{"name":"swift","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/swift?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.5.0-0ubuntu1","2.7.0-0ubuntu2","2.7.0-0ubuntu2.1","2.7.1-0ubuntu1","2.7.1-0ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_version":"2.7.1-0ubuntu2","binary_name":"python-swift"},{"binary_name":"swift","binary_version":"2.7.1-0ubuntu2"},{"binary_version":"2.7.1-0ubuntu2","binary_name":"swift-account"},{"binary_version":"2.7.1-0ubuntu2","binary_name":"swift-container"},{"binary_name":"swift-object","binary_version":"2.7.1-0ubuntu2"},{"binary_name":"swift-object-expirer","binary_version":"2.7.1-0ubuntu2"},{"binary_name":"swift-proxy","binary_version":"2.7.1-0ubuntu2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50221.json"}},{"package":{"name":"swift","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/swift?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.15.1-0ubuntu3","2.16.0-0ubuntu1","2.16.0-0ubuntu2","2.17.0-0ubuntu1","2.17.1-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.17.1-0ubuntu1","binary_name":"python-swift"},{"binary_version":"2.17.1-0ubuntu1","binary_name":"swift"},{"binary_version":"2.17.1-0ubuntu1","binary_name":"swift-account"},{"binary_name":"swift-container","binary_version":"2.17.1-0ubuntu1"},{"binary_name":"swift-object","binary_version":"2.17.1-0ubuntu1"},{"binary_name":"swift-object-expirer","binary_version":"2.17.1-0ubuntu1"},{"binary_version":"2.17.1-0ubuntu1","binary_name":"swift-proxy"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50221.json"}},{"package":{"name":"swift","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/swift?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.23.0-0ubuntu1","2.23.1-0ubuntu1","2.24.0~git2019121715.e890b0f0f-0ubuntu1","2.24.0-0ubuntu1","2.24.1~git2020032711.712bf3c9f-0ubuntu2","2.24.1~git2020041316.a495f1e32-0ubuntu1","2.25.0-0ubuntu0.20.04.1","2.25.1-0ubuntu1","2.25.2-0ubuntu1","2.25.2-0ubuntu1.1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-swift","binary_version":"2.25.2-0ubuntu1.1"},{"binary_name":"swift","binary_version":"2.25.2-0ubuntu1.1"},{"binary_version":"2.25.2-0ubuntu1.1","binary_name":"swift-account"},{"binary_name":"swift-container","binary_version":"2.25.2-0ubuntu1.1"},{"binary_name":"swift-object","binary_version":"2.25.2-0ubuntu1.1"},{"binary_version":"2.25.2-0ubuntu1.1","binary_name":"swift-object-expirer"},{"binary_name":"swift-proxy","binary_version":"2.25.2-0ubuntu1.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50221.json"}},{"package":{"name":"swift","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/swift?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.28.0+git2021090911.5d52afbe4-0ubuntu1","2.28.0+git2021120815.1859f2e16-0ubuntu1","2.28.0+git2021121320.876377435-0ubuntu1","2.28.0+git2022011309.32da73f5c-0ubuntu1","2.29.0+git2022030314.3ff3076ce-0ubuntu1","2.29.0+git2022030314.3ff3076ce-0ubuntu2","2.29.1-0ubuntu1","2.29.2-0ubuntu1","2.29.2-0ubuntu1.1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.29.2-0ubuntu1.1","binary_name":"python3-swift"},{"binary_name":"swift","binary_version":"2.29.2-0ubuntu1.1"},{"binary_name":"swift-account","binary_version":"2.29.2-0ubuntu1.1"},{"binary_version":"2.29.2-0ubuntu1.1","binary_name":"swift-container"},{"binary_name":"swift-object","binary_version":"2.29.2-0ubuntu1.1"},{"binary_name":"swift-object-expirer","binary_version":"2.29.2-0ubuntu1.1"},{"binary_version":"2.29.2-0ubuntu1.1","binary_name":"swift-proxy"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50221.json"}},{"package":{"name":"swift","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/swift?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.32.0+git2023090714.8ce961ed-0ubuntu1","2.32.0+git2024021508.3aba22fd-0ubuntu1","2.32.0+git2024030809.4135133a-0ubuntu1","2.33.0-0ubuntu1","2.33.0-0ubuntu1.1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-swift","binary_version":"2.33.0-0ubuntu1.1"},{"binary_name":"swift","binary_version":"2.33.0-0ubuntu1.1"},{"binary_name":"swift-account","binary_version":"2.33.0-0ubuntu1.1"},{"binary_name":"swift-container","binary_version":"2.33.0-0ubuntu1.1"},{"binary_name":"swift-object","binary_version":"2.33.0-0ubuntu1.1"},{"binary_version":"2.33.0-0ubuntu1.1","binary_name":"swift-object-expirer"},{"binary_version":"2.33.0-0ubuntu1.1","binary_name":"swift-proxy"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50221.json"}},{"package":{"name":"swift","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/swift?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.35.0-0ubuntu1","2.35.0+git2025070714.1428eb3b5-0ubuntu1","2.36.0-0ubuntu1","2.36.0-0ubuntu1.1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-swift","binary_version":"2.36.0-0ubuntu1.1"},{"binary_version":"2.36.0-0ubuntu1.1","binary_name":"swift"},{"binary_name":"swift-account","binary_version":"2.36.0-0ubuntu1.1"},{"binary_version":"2.36.0-0ubuntu1.1","binary_name":"swift-container"},{"binary_name":"swift-object","binary_version":"2.36.0-0ubuntu1.1"},{"binary_version":"2.36.0-0ubuntu1.1","binary_name":"swift-object-expirer"},{"binary_name":"swift-proxy","binary_version":"2.36.0-0ubuntu1.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50221.json"}},{"package":{"name":"swift","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/swift?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.36.0-0ubuntu1","2.37.0-0ubuntu1","2.37.1-0ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-swift","binary_version":"2.37.1-0ubuntu2"},{"binary_name":"swift","binary_version":"2.37.1-0ubuntu2"},{"binary_name":"swift-account","binary_version":"2.37.1-0ubuntu2"},{"binary_version":"2.37.1-0ubuntu2","binary_name":"swift-container"},{"binary_version":"2.37.1-0ubuntu2","binary_name":"swift-object"},{"binary_name":"swift-object-expirer","binary_version":"2.37.1-0ubuntu2"},{"binary_name":"swift-proxy","binary_version":"2.37.1-0ubuntu2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50221.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}