#1142973 OSSA-2026-031 Swift: Proxy denial of service via Accept header (CVE-2026-pending)

Package:
src:swift
Source:
src:swift
Submitter:
Thomas Goirand
Date:
2026-07-29 08:21:03 UTC
Severity:
normal
Tags:
#1142973#5
Date:
2026-07-29 07:28:26 UTC
From:
To:
As per upstream announce at:
https://security.openstack.org/ossa/OSSA-2026-031.html

:Date: July 28, 2026
:CVE: CVE-2026-pending


Affects
~~~~~~~
- Swift: >=1.9.1 <2.35.4, >=2.36.0 <2.36.3, >=2.37.0 <2.37.3, ==2.38.0


Description
~~~~~~~~~~~
Christian Schwede from NVIDIA reported a denial of service vulnerability in
Swift's proxy server. The Accept header parser is vulnerable to catastrophic
regular expression backtracking. An unauthenticated attacker can send crafted
requests that exhaust proxy worker threads, rendering the service unavailable.
All deployments running Swift proxy with versions between 1.9.1 and the fixed
releases listed below are affected.



Patches
~~~~~~~
- https://review.opendev.org/998953 (2025.1/epoxy)
- https://review.opendev.org/998952 (2025.2/flamingo)
- https://review.opendev.org/998951 (2026.1/gazpacho)
- https://review.opendev.org/998950 (2026.2/hibiscus (development))


Credits
~~~~~~~
- Christian Schwede from NVIDIA


References
~~~~~~~~~~
- https://launchpad.net/bugs/2158771
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending

#1142973#8
Date:
2026-07-29 07:48:42 UTC
From:
To:
Hello,

Bug #1142973 in swift reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/swift/-/commit/8dd6abfc4b1198dede519f46514415e4a75adf94
------------------------------------------------------------------------
* OSSA-2026-030 / CVE-2026-pending1: Swift S3API header authorization bypass.
    Applied upstream patch:
    - "s3api: require signing of sensitive SigV4 x-amz headers"
    - "s3api: drop native Swift control headers from client requests"
    (Closes: #1142972).
  * OSSA-2026-031 / CVE-2026-pending2: proxy denial of service via Accept header.
    Applied upstream patch:
    - swob: avoid excessive backtracking in Accept parser
    (Closes: #1142973).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142973

#1142973#13
Date:
2026-07-29 07:52:37 UTC
From:
To:
Hello,

Bug #1142973 in swift reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/swift/-/commit/77000803bacdf50c44b1a7997089da6380d65e60
------------------------------------------------------------------------
* OSSA-2026-030 / CVE-2026-pending1: Swift S3API header authorization bypass.
    Applied upstream patch:
    - "s3api: require signing of sensitive SigV4 x-amz headers"
    - "s3api: drop native Swift control headers from client requests"
    (Closes: #1142972).
  * OSSA-2026-031 / CVE-2026-pending2: proxy denial of service via Accept header.
    Applied upstream patch:
    - swob: avoid excessive backtracking in Accept parser
    (Closes: #1142973).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142973

#1142973#16
Date:
2026-07-29 07:56:38 UTC
From:
To:
Hello,

Bug #1142973 in swift reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/swift/-/commit/267c44a33a50c2995e459abd0aefaaf70e7a1589
------------------------------------------------------------------------
* OSSA-2026-030 / CVE-2026-pending1: Swift S3API header authorization bypass.
    Applied upstream patch:
    - "s3api: require signing of sensitive SigV4 x-amz headers"
    - "s3api: drop native Swift control headers from client requests"
    (Closes: #1142972).
  * OSSA-2026-031 / CVE-2026-pending2: proxy denial of service via Accept header.
    Applied upstream patch:
    - swob: avoid excessive backtracking in Accept parser
    (Closes: #1142973).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142973

#1142973#19
Date:
2026-07-29 08:03:31 UTC
From:
To:
Hello,

Bug #1142973 in swift reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/swift/-/commit/b87a883506c70e34b31444ac07f01b550ddd49ac
------------------------------------------------------------------------
* OSSA-2026-031 / CVE-2026-pending2: proxy denial of service via Accept header.
    Applied upstream patch:
    - swob: avoid excessive backtracking in Accept parser
    (Closes: #1142973).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142973

#1142973#22
Date:
2026-07-29 08:05:32 UTC
From:
To:
Hello,

Bug #1142973 in swift reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/swift/-/commit/1b19818dd7c323bbffe0a78595e086abee626475
------------------------------------------------------------------------
* OSSA-2026-031 / CVE-2026-pending2: proxy denial of service via Accept header.
    Applied upstream patch:
    - swob: avoid excessive backtracking in Accept parser
    (Closes: #1142973).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142973

#1142973#27
Date:
2026-07-29 08:20:10 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
swift, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142973@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated swift package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 22 Jul 2026 21:04:34 +0200
Source: swift
Architecture: source
Version: 2.37.1-6
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1142972 1142973
Changes:
 swift (2.37.1-6) unstable; urgency=high
 .
   * OSSA-2026-030 / CVE-2026-pending1: Swift S3API header authorization bypass.
     Applied upstream patch:
     - "s3api: require signing of sensitive SigV4 x-amz headers"
     - "s3api: drop native Swift control headers from client requests"
     (Closes: #1142972).
   * OSSA-2026-031 / CVE-2026-pending2: proxy denial of service via Accept header.
     Applied upstream patch:
     - swob: avoid excessive backtracking in Accept parser
     (Closes: #1142973).
Checksums-Sha1:
 3ddb2574a4805f76a81654b3f5809086a8c4d1a0 3159 swift_2.37.1-6.dsc
 f9a36c91ffc43c5b98c435fcead18398bc6f50ee 39620 swift_2.37.1-6.debian.tar.xz
 f35f562e8037df524482a325dcb9c00bb86be765 14328 swift_2.37.1-6_amd64.buildinfo
Checksums-Sha256:
 21b5514d896202826fb0478cf05fdd49ceab678513ad10e2a2b0e4da9801c81b 3159 swift_2.37.1-6.dsc
 a7e8431b394d69bfcff69e1217a3b3655aca5b76630ebdacec607d2ed057918c 39620 swift_2.37.1-6.debian.tar.xz
 b0adfcce58a3165e16fb815d4568952fcc5e4062795b318360655c3a2d1ad642 14328 swift_2.37.1-6_amd64.buildinfo
Files:
 1b108b981048672da66821da9fdd5b27 3159 net optional swift_2.37.1-6.dsc
 5abc0a61c988837ab58fd6060205394c 39620 net optional swift_2.37.1-6.debian.tar.xz
 d6c70569a206db47b5e7691892591317 14328 net optional swift_2.37.1-6_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmppsGUACgkQ1BatFaxr
Q/6oJxAAnpw6c5Rf+KGcYVx/qFpRr0h2+5Frvtr2ojCnwNQkuQZys9dDVOW5lMFL
UjD/f/NKVTEblqdBkbbMAnBw4MBHhvjLiyoaEafNvsxURYJ/53m7S133GfvYqqgG
nUrpNiIa8my4U79QmMF8cxGZcWJtXgH1riEDU41sRl/KPGyElCftE/hGT+Arong0
0ZMav0PvMEIac71/+Du3GIv0Y3iBWLY1lDlw3jj9o9HU9njVSCZE0zxro+0dIsoK
iisK/d9kNqsex2MxN+7+XAdCdUFkHgsbPUyvCCFZw7DzN+HJOSMzHIHm9+fafGhI
5F4xdD+H4jpwkiSmhzannHRayFvfkWvLceBCxoDrGE/7IL9w7EeCvw7HNylj/7Jm
LfOOq61jMuEm5G6sM9JilVX1V7bVJGMOtj8ajXeHP5hk+6OG0NksRyQkTZUWDapP
ICOkwaEAnd5qF077jK3PhxKMCrJBP9ZzUTfRX4PKjq73Tr9b9DkQtvXHiuuPeovV
gpBrfSNzWOGKbLQH99yOB/cXVoH4P4dBtjxN0/0La84YgxF9w7aEnk/fRG9HgFyL
EtOln+BOU0J6xSNjoLks2srIGGh3WsKO0RWsD65Ps16NmemlJdXfTBJrvP2pj9Nx
ApjSYt7SkjykktxDVzB55W4O9WSq2gGvcEBHyqrOmvyiSe70SS8=
=qA/P
-----END PGP SIGNATURE-----