#1142973 OSSA-2026-031 Swift: Proxy denial of service via Accept header (CVE-2026-pending)

Package:
src:swift
Source:
src:swift
Submitter:
Thomas Goirand
Date:
2026-08-24 22:37:02 UTC
Severity:
normal
Tags:
#1142973#5
Date:
2026-07-29 07:28:26 UTC
From:
To:
As per upstream announce at:
https://security.openstack.org/ossa/OSSA-2026-031.html

:Date: July 28, 2026
:CVE: CVE-2026-pending


Affects
~~~~~~~
- Swift: >=1.9.1 <2.35.4, >=2.36.0 <2.36.3, >=2.37.0 <2.37.3, ==2.38.0


Description
~~~~~~~~~~~
Christian Schwede from NVIDIA reported a denial of service vulnerability in
Swift's proxy server. The Accept header parser is vulnerable to catastrophic
regular expression backtracking. An unauthenticated attacker can send crafted
requests that exhaust proxy worker threads, rendering the service unavailable.
All deployments running Swift proxy with versions between 1.9.1 and the fixed
releases listed below are affected.



Patches
~~~~~~~
- https://review.opendev.org/998953 (2025.1/epoxy)
- https://review.opendev.org/998952 (2025.2/flamingo)
- https://review.opendev.org/998951 (2026.1/gazpacho)
- https://review.opendev.org/998950 (2026.2/hibiscus (development))


Credits
~~~~~~~
- Christian Schwede from NVIDIA


References
~~~~~~~~~~
- https://launchpad.net/bugs/2158771
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending

#1142973#8
Date:
2026-07-29 07:48:42 UTC
From:
To:
Hello,

Bug #1142973 in swift reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/swift/-/commit/8dd6abfc4b1198dede519f46514415e4a75adf94
------------------------------------------------------------------------
* OSSA-2026-030 / CVE-2026-pending1: Swift S3API header authorization bypass.
    Applied upstream patch:
    - "s3api: require signing of sensitive SigV4 x-amz headers"
    - "s3api: drop native Swift control headers from client requests"
    (Closes: #1142972).
  * OSSA-2026-031 / CVE-2026-pending2: proxy denial of service via Accept header.
    Applied upstream patch:
    - swob: avoid excessive backtracking in Accept parser
    (Closes: #1142973).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142973

#1142973#13
Date:
2026-07-29 07:52:37 UTC
From:
To:
Hello,

Bug #1142973 in swift reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/swift/-/commit/77000803bacdf50c44b1a7997089da6380d65e60
------------------------------------------------------------------------
* OSSA-2026-030 / CVE-2026-pending1: Swift S3API header authorization bypass.
    Applied upstream patch:
    - "s3api: require signing of sensitive SigV4 x-amz headers"
    - "s3api: drop native Swift control headers from client requests"
    (Closes: #1142972).
  * OSSA-2026-031 / CVE-2026-pending2: proxy denial of service via Accept header.
    Applied upstream patch:
    - swob: avoid excessive backtracking in Accept parser
    (Closes: #1142973).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142973

#1142973#16
Date:
2026-07-29 07:56:38 UTC
From:
To:
Hello,

Bug #1142973 in swift reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/swift/-/commit/267c44a33a50c2995e459abd0aefaaf70e7a1589
------------------------------------------------------------------------
* OSSA-2026-030 / CVE-2026-pending1: Swift S3API header authorization bypass.
    Applied upstream patch:
    - "s3api: require signing of sensitive SigV4 x-amz headers"
    - "s3api: drop native Swift control headers from client requests"
    (Closes: #1142972).
  * OSSA-2026-031 / CVE-2026-pending2: proxy denial of service via Accept header.
    Applied upstream patch:
    - swob: avoid excessive backtracking in Accept parser
    (Closes: #1142973).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142973

#1142973#19
Date:
2026-07-29 08:03:31 UTC
From:
To:
Hello,

Bug #1142973 in swift reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/swift/-/commit/b87a883506c70e34b31444ac07f01b550ddd49ac
------------------------------------------------------------------------
* OSSA-2026-031 / CVE-2026-pending2: proxy denial of service via Accept header.
    Applied upstream patch:
    - swob: avoid excessive backtracking in Accept parser
    (Closes: #1142973).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142973

#1142973#22
Date:
2026-07-29 08:05:32 UTC
From:
To:
Hello,

Bug #1142973 in swift reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/swift/-/commit/1b19818dd7c323bbffe0a78595e086abee626475
------------------------------------------------------------------------
* OSSA-2026-031 / CVE-2026-pending2: proxy denial of service via Accept header.
    Applied upstream patch:
    - swob: avoid excessive backtracking in Accept parser
    (Closes: #1142973).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142973

#1142973#27
Date:
2026-07-29 08:20:10 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
swift, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142973@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated swift package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 22 Jul 2026 21:04:34 +0200
Source: swift
Architecture: source
Version: 2.37.1-6
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1142972 1142973
Changes:
 swift (2.37.1-6) unstable; urgency=high
 .
   * OSSA-2026-030 / CVE-2026-pending1: Swift S3API header authorization bypass.
     Applied upstream patch:
     - "s3api: require signing of sensitive SigV4 x-amz headers"
     - "s3api: drop native Swift control headers from client requests"
     (Closes: #1142972).
   * OSSA-2026-031 / CVE-2026-pending2: proxy denial of service via Accept header.
     Applied upstream patch:
     - swob: avoid excessive backtracking in Accept parser
     (Closes: #1142973).
Checksums-Sha1:
 3ddb2574a4805f76a81654b3f5809086a8c4d1a0 3159 swift_2.37.1-6.dsc
 f9a36c91ffc43c5b98c435fcead18398bc6f50ee 39620 swift_2.37.1-6.debian.tar.xz
 f35f562e8037df524482a325dcb9c00bb86be765 14328 swift_2.37.1-6_amd64.buildinfo
Checksums-Sha256:
 21b5514d896202826fb0478cf05fdd49ceab678513ad10e2a2b0e4da9801c81b 3159 swift_2.37.1-6.dsc
 a7e8431b394d69bfcff69e1217a3b3655aca5b76630ebdacec607d2ed057918c 39620 swift_2.37.1-6.debian.tar.xz
 b0adfcce58a3165e16fb815d4568952fcc5e4062795b318360655c3a2d1ad642 14328 swift_2.37.1-6_amd64.buildinfo
Files:
 1b108b981048672da66821da9fdd5b27 3159 net optional swift_2.37.1-6.dsc
 5abc0a61c988837ab58fd6060205394c 39620 net optional swift_2.37.1-6.debian.tar.xz
 d6c70569a206db47b5e7691892591317 14328 net optional swift_2.37.1-6_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmppsGUACgkQ1BatFaxr
Q/6oJxAAnpw6c5Rf+KGcYVx/qFpRr0h2+5Frvtr2ojCnwNQkuQZys9dDVOW5lMFL
UjD/f/NKVTEblqdBkbbMAnBw4MBHhvjLiyoaEafNvsxURYJ/53m7S133GfvYqqgG
nUrpNiIa8my4U79QmMF8cxGZcWJtXgH1riEDU41sRl/KPGyElCftE/hGT+Arong0
0ZMav0PvMEIac71/+Du3GIv0Y3iBWLY1lDlw3jj9o9HU9njVSCZE0zxro+0dIsoK
iisK/d9kNqsex2MxN+7+XAdCdUFkHgsbPUyvCCFZw7DzN+HJOSMzHIHm9+fafGhI
5F4xdD+H4jpwkiSmhzannHRayFvfkWvLceBCxoDrGE/7IL9w7EeCvw7HNylj/7Jm
LfOOq61jMuEm5G6sM9JilVX1V7bVJGMOtj8ajXeHP5hk+6OG0NksRyQkTZUWDapP
ICOkwaEAnd5qF077jK3PhxKMCrJBP9ZzUTfRX4PKjq73Tr9b9DkQtvXHiuuPeovV
gpBrfSNzWOGKbLQH99yOB/cXVoH4P4dBtjxN0/0La84YgxF9w7aEnk/fRG9HgFyL
EtOln+BOU0J6xSNjoLks2srIGGh3WsKO0RWsD65Ps16NmemlJdXfTBJrvP2pj9Nx
ApjSYt7SkjykktxDVzB55W4O9WSq2gGvcEBHyqrOmvyiSe70SS8=
=qA/P
-----END PGP SIGNATURE-----

#1142973#38
Date:
2026-08-24 22:34:19 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
swift, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142973@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated swift package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 17 Aug 2026 11:01:41 +0200
Source: swift
Architecture: source
Version: 2.35.1-0+deb13u3
Distribution: trixie-security
Urgency: medium
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1140678 1142972 1142973
Changes:
 swift (2.35.1-0+deb13u3) trixie-security; urgency=medium
 .
   * CVE-2026-71191 / OSSA-2026-030: Swift S3API header authorization bypass.
     Applied upstream patch:
     - "s3api: require signing of sensitive SigV4 x-amz headers"
     - "s3api: drop native Swift control headers from client requests"
     (Closes: #1142972).
   * CVE-2026-71192 / OSSA-2026-031: proxy denial of service via Accept header.
     Applied upstream patch:
     - "swob: avoid excessive backtracking in Accept parser"
     (Closes: #1142973).
   * CVE-2026-50221: Swift proxy-server SSRF via internal update header
     injection: applied upstream patch: Block internal update headers at the
     gatekeeper (Closes: #1140678).
Checksums-Sha1:
 1e47d7458955ec21348b403ee58c641d130fef46 3165 swift_2.35.1-0+deb13u3.dsc
 5dc7039ecfd608a05ec987bfe49cc2fb6f587148 2706568 swift_2.35.1.orig.tar.xz
 ae854c83db3f911d226f3887298bab6765f74d58 38196 swift_2.35.1-0+deb13u3.debian.tar.xz
 223f79ebb4a2c3b64035c335a7dd7e8a155dfa3d 14846 swift_2.35.1-0+deb13u3_amd64.buildinfo
Checksums-Sha256:
 6730cd82004b325f2452fd3297d93e31676cb9f6fd0911e8df288590d4bc64cb 3165 swift_2.35.1-0+deb13u3.dsc
 ee2bba0d77ce5bccc04db93d531ddd65ee092a1ce1070b0995f1ca8f7a3a5beb 2706568 swift_2.35.1.orig.tar.xz
 89a1262a296f09c1816ef76b9348e08989b5e6b823abe760dbdf54a6a1e84096 38196 swift_2.35.1-0+deb13u3.debian.tar.xz
 6e3d18523197fcd2c7b15e4c82efc20d4cec390485e114b811586affedcd2944 14846 swift_2.35.1-0+deb13u3_amd64.buildinfo
Files:
 65ee8fbc7f3cb844f495dd8a5688fcf1 3165 net optional swift_2.35.1-0+deb13u3.dsc
 0fe9e0f72d050292fb9182633c9462af 2706568 net optional swift_2.35.1.orig.tar.xz
 f5600cd5a7861182df88df01583dee0e 38196 net optional swift_2.35.1-0+deb13u3.debian.tar.xz
 3293c3cbcfa68c3fe971b41684523cb7 14846 net optional swift_2.35.1-0+deb13u3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqEFn0ACgkQ1BatFaxr
Q/6TuxAAgSko0IqFQmIwH6feQEEhUdZlfhz3u4vllnabHtb1ZhuF5QGRHR+cVmi4
DHYQJPJii72AKRRQetmRjrXW4offcb78wl4chyz0cOGoF95joLrcJkqtB1MXlun9
+o2W/GI6MByIl9mWdXnVWmrz/VRI00ToMmg6WkOwDnxi1LFvKBBC4QmGg+ONvnpI
vidMwwD2SuH/unVjpmlFkoFUCkjBVo6UFB+f4zII9mKUrf0aWgSJsWh6XjPV/0dI
/51KywAsVtPBF9hCNwvYmhlcnqNeS28zusMXjiNXa6YPzQKhSvYC4/IwWC7kaCnf
ukyVJj3wLNOY5xsQgV14URymS4lixA7Sgn2EhdHZP/nvkfL+/eNO7r2+EEcNTcVp
NG+etV7acgYulYq/udbZ8y9SkeCzR+5QdJDRfVF50i6Ocbv+Ef9YB46zIzSXF/vV
dMrqYsNhd4cqspoDFiFXzDDZarJmIIEpg1pV+jAOMlOSQmifwB0GP8qp2E+eMe2b
M/54qgO8QU13LsbT4fXlRgIJJZmC59Bs2xrdicAJM24I+ZziSNnKOaTcnnC6TYgk
21O5x4qMyCMOYurfNsCqed3PGe9kEI+QmSPqlTq5IjdCGXfw8Axr0VOv5Vaz3xy6
B1US0F+qaH0D8L9Mxlib6nTakcDFrxlSFHe0mBjvAKf92Qp/2TA=
=0nDe
-----END PGP SIGNATURE-----