{"id":"UBUNTU-CVE-2026-97149","details":"In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, and path, and thus the list of disallowed headers is the only defense against a signed PUT request changing what the request does. An attacker holding a PUT TempURL for a single object can add an X-Copy-From header naming any object in the same account; the copy middleware copies that object to the destination, and the attacker then reads the victim's data back with a GET TempURL for the destination object. Copies across account boundaries are rejected. Only deployments using the shipped default proxy pipeline (tempurl and copy middleware) with account-level TempURL keys are affected.","modified":"2026-09-25T06:37:31.255044486Z","published":"2026-09-24T00:00:00Z","upstream":["CVE-2026-97149"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-97149"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-97149"},{"type":"REPORT","url":"https://launchpad.net/bugs/2166876"},{"type":"REPORT","url":"https://security.openstack.org/ossa/OSSA-2026-041.html"}],"affected":[{"package":{"name":"swift","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/swift?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.5.0-0ubuntu1","2.7.0-0ubuntu2","2.7.0-0ubuntu2.1","2.7.1-0ubuntu1","2.7.1-0ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_version":"2.7.1-0ubuntu2","binary_name":"python-swift"},{"binary_name":"swift","binary_version":"2.7.1-0ubuntu2"},{"binary_version":"2.7.1-0ubuntu2","binary_name":"swift-account"},{"binary_name":"swift-container","binary_version":"2.7.1-0ubuntu2"},{"binary_version":"2.7.1-0ubuntu2","binary_name":"swift-object"},{"binary_version":"2.7.1-0ubuntu2","binary_name":"swift-object-expirer"},{"binary_name":"swift-proxy","binary_version":"2.7.1-0ubuntu2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-97149.json"}},{"package":{"name":"swift","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/swift?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.15.1-0ubuntu3","2.16.0-0ubuntu1","2.16.0-0ubuntu2","2.17.0-0ubuntu1","2.17.1-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"python-swift","binary_version":"2.17.1-0ubuntu1"},{"binary_name":"swift","binary_version":"2.17.1-0ubuntu1"},{"binary_version":"2.17.1-0ubuntu1","binary_name":"swift-account"},{"binary_name":"swift-container","binary_version":"2.17.1-0ubuntu1"},{"binary_name":"swift-object","binary_version":"2.17.1-0ubuntu1"},{"binary_version":"2.17.1-0ubuntu1","binary_name":"swift-object-expirer"},{"binary_name":"swift-proxy","binary_version":"2.17.1-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-97149.json"}},{"package":{"name":"swift","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/swift?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.23.0-0ubuntu1","2.23.1-0ubuntu1","2.24.0~git2019121715.e890b0f0f-0ubuntu1","2.24.0-0ubuntu1","2.24.1~git2020032711.712bf3c9f-0ubuntu2","2.24.1~git2020041316.a495f1e32-0ubuntu1","2.25.0-0ubuntu0.20.04.1","2.25.1-0ubuntu1","2.25.2-0ubuntu1","2.25.2-0ubuntu1.1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.25.2-0ubuntu1.1","binary_name":"python3-swift"},{"binary_name":"swift","binary_version":"2.25.2-0ubuntu1.1"},{"binary_version":"2.25.2-0ubuntu1.1","binary_name":"swift-account"},{"binary_name":"swift-container","binary_version":"2.25.2-0ubuntu1.1"},{"binary_version":"2.25.2-0ubuntu1.1","binary_name":"swift-object"},{"binary_name":"swift-object-expirer","binary_version":"2.25.2-0ubuntu1.1"},{"binary_name":"swift-proxy","binary_version":"2.25.2-0ubuntu1.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-97149.json"}},{"package":{"name":"swift","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/swift?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.28.0+git2021090911.5d52afbe4-0ubuntu1","2.28.0+git2021120815.1859f2e16-0ubuntu1","2.28.0+git2021121320.876377435-0ubuntu1","2.28.0+git2022011309.32da73f5c-0ubuntu1","2.29.0+git2022030314.3ff3076ce-0ubuntu1","2.29.0+git2022030314.3ff3076ce-0ubuntu2","2.29.1-0ubuntu1","2.29.2-0ubuntu1","2.29.2-0ubuntu1.1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-swift","binary_version":"2.29.2-0ubuntu1.1"},{"binary_name":"swift","binary_version":"2.29.2-0ubuntu1.1"},{"binary_name":"swift-account","binary_version":"2.29.2-0ubuntu1.1"},{"binary_name":"swift-container","binary_version":"2.29.2-0ubuntu1.1"},{"binary_name":"swift-object","binary_version":"2.29.2-0ubuntu1.1"},{"binary_version":"2.29.2-0ubuntu1.1","binary_name":"swift-object-expirer"},{"binary_version":"2.29.2-0ubuntu1.1","binary_name":"swift-proxy"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-97149.json"}},{"package":{"name":"swift","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/swift?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.32.0+git2023090714.8ce961ed-0ubuntu1","2.32.0+git2024021508.3aba22fd-0ubuntu1","2.32.0+git2024030809.4135133a-0ubuntu1","2.33.0-0ubuntu1","2.33.0-0ubuntu1.1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.33.0-0ubuntu1.1","binary_name":"python3-swift"},{"binary_name":"swift","binary_version":"2.33.0-0ubuntu1.1"},{"binary_name":"swift-account","binary_version":"2.33.0-0ubuntu1.1"},{"binary_name":"swift-container","binary_version":"2.33.0-0ubuntu1.1"},{"binary_name":"swift-object","binary_version":"2.33.0-0ubuntu1.1"},{"binary_version":"2.33.0-0ubuntu1.1","binary_name":"swift-object-expirer"},{"binary_version":"2.33.0-0ubuntu1.1","binary_name":"swift-proxy"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-97149.json"}},{"package":{"name":"swift","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/swift?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.36.0-0ubuntu1","2.37.0-0ubuntu1","2.37.1-0ubuntu2","2.37.1-0ubuntu2.1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-swift","binary_version":"2.37.1-0ubuntu2.1"},{"binary_name":"swift","binary_version":"2.37.1-0ubuntu2.1"},{"binary_version":"2.37.1-0ubuntu2.1","binary_name":"swift-account"},{"binary_version":"2.37.1-0ubuntu2.1","binary_name":"swift-container"},{"binary_name":"swift-object","binary_version":"2.37.1-0ubuntu2.1"},{"binary_version":"2.37.1-0ubuntu2.1","binary_name":"swift-object-expirer"},{"binary_name":"swift-proxy","binary_version":"2.37.1-0ubuntu2.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-97149.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]}