As per upstream announce: https://security.openstack.org/ossa/OSSA-2026-036.html Date: August 19, 2026 CVE: CVE-2026-pending Affects: Aodh: >=10.0.0 <20.0.1, ==21.0.0, ==22.0.0 Watcher: >=4.0.0 <14.1.2, >=15.0.0 <15.1.2, >=16.0.0 <16.0.2 Description: Chen YuXiang of the Institute of Computing Technology, Chinese Academy of Sciences reported that OpenStack Aodh does not enforce project scope on the alarm listing API when the all_projects query parameter is supplied with a false value. A non-admin user holding only the reader role can list alarms belonging to other projects, optionally targeting a specific project, exposing alarm metadata such as webhook action URLs, signal endpoints, and project identifiers. All Aodh deployments are affected. The same reporter found that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit’s webhook URL, for example from the Aodh alarm metadata leaked above, can start an EVENT audit and its associated action plan regardless of their own project or role. All Watcher deployments are affected. Patches: https://review.opendev.org/1001503 (2025.1/epoxy (aodh)) https://review.opendev.org/1001509 (2025.1/epoxy (watcher)) https://review.opendev.org/1001502 (2025.2/flamingo (aodh)) https://review.opendev.org/1001508 (2025.2/flamingo (watcher)) https://review.opendev.org/1001501 (2026.1/gazpacho (aodh)) https://review.opendev.org/1001507 (2026.1/gazpacho (watcher)) https://review.opendev.org/1001500 (2026.2/hibiscus (development) (aodh)) https://review.opendev.org/1001505 (2026.2/hibiscus (development) (watcher)) Credits: Chen YuXiang from Institute of Computing Technology, Chinese Academy of Sciences References: https://launchpad.net/bugs/2161276 https://launchpad.net/bugs/2161771 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending Notes: A CVE identifier was requested from MITRE for the aodh vulnerability on 2026-08-03. The CVE will be added to this advisory by errata once assigned.
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/4d789b90c510a3b307eb51a16f2f3b41d47523b9 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-03X: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/14394ae17f71b082e377d52c0ca85ae36bc44f0e ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/6f1b305736cd0479566ba1b0cd847ae575e68522 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/55d0ed2c02f704414497fa9497ffb23f6e69c624 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/59004027185a6cf3fd1a977fbe25a724f41ecb89 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/8060a3e724ee38434e9c4a8ca02220b27e2c29b4 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/16ac30ff691c87edcdda6387daa85c1897c09329 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/ecc9aacc731c43f79e4f1732198716a28a0d565a ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/f75635916b4a82ef228e26a55be12a6110ef6520 ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-03X: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/bf70f41c2fe696c3f77528f5b4c7d88286955cfc ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/834a4c76e9a2eab4b24f142e95c4da2d2492d7ff ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/30156bfdfc26b52508040071775e264bca8ffef2 ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/dd7dad460101fe59ec054c2282daab5fad3627a1 ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/0e38cd1e64d306560871ff47d745fe80545d69d4 ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/1655783ff5f99bbcf4ec75cda0cd8ab7253bf64c ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/0f6bf58aa69cbd8405bfe7646e97c6bde2a46570 ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/676d77b113265abc78b717952d20f79377b08d95 ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/a07bc19294568ba5ecc2b5b250288dc472a8fe78 ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/a942af5aa2fe12d2f9367752ff508c16d6a2ea8b ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
We believe that the bug you reported is fixed in the latest version of
aodh, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1144879@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated aodh package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 12 Aug 2026 09:52:46 +0200
Source: aodh
Architecture: source
Version: 22.0.0-3
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1144879
Changes:
aodh (22.0.0-3) unstable; urgency=high
.
* CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project
scope when the all_projects query parameter is present with a false value.
A non-admin project reader can list alarms belonging to other projects by
passing all_projects=false in a list query, optionally combined with a
foreign project_id to target a specific project. Leaked alarm data includes
trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
upstream patch: "Fix all_projects=false bypass project scope"
(Closes: #1144879).
Checksums-Sha1:
3bd1b94b8580af7c5df0a2c4add5ac16863ab492 3532 aodh_22.0.0-3.dsc
0d0f799311aca291c1cd9cfcd6791c8f464a2602 13444 aodh_22.0.0-3.debian.tar.xz
e08793efee0a5db1a2c53a4d987cbe8ae73c5f1a 17600 aodh_22.0.0-3_amd64.buildinfo
Checksums-Sha256:
165778b0999339843f7c1f904a7c8f85e1c50f05b990332393be3e5c2ea085c8 3532 aodh_22.0.0-3.dsc
f864ba03bd4b945b5279a3c5be823715be4dc134b7ed11842a6e63392200a603 13444 aodh_22.0.0-3.debian.tar.xz
dc7b2d53b69a146579d81657bd5c37d58d3509c08def31540556cd58a8f28ff9 17600 aodh_22.0.0-3_amd64.buildinfo
Files:
b479d26a723ca5169cdbca4653b17aed 3532 web optional aodh_22.0.0-3.dsc
d4342762b689f2953c6e4b75befe6ba5 13444 web optional aodh_22.0.0-3.debian.tar.xz
35e453ec4fbf3c0284afe233e2e6e64e 17600 web optional aodh_22.0.0-3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqMTw8ACgkQ1BatFaxr
Q/7yGQ//dcbAwfsI7AlxmUM3gdfbFijMGuq47Y+wURmvSMWdKWj3mwvuCQYceJl8
zjSI89nCjsxSB+XoCREjIgROpGefJDUPO6U67QJVXIDYK5KGqzuDwPWRE9llZNIM
11/Qi+yjic/w8TjG6OzIIQ8NIIOeZUSdIkC1Au/7ZXbrb7obRE12X8iuXomrNbj3
Sjow5bxtRZ2bQRBtlyul4/zwQqq3oKtnMgTqwzqUA16j9A6MC61AcqRhcc8gKtpr
p5KC0xzUEioM8VwyIcB4jMSisELgneH1dBNhsZWxEoCF98s/07bNyL0v5dGmJikP
BmJnfAsc3oCd/7TrZBtiD9wVuMhO6v5oiPzMZPkgI+eSkAp1W5Ij38r51sj0EV3U
eO59M0NQKVQ3loTY/gU7sXSkFFtJzvYR40m2IEEkymZ6NDgn13em6eZ8vZyFCeIW
O6CbQBroRgdo2p8ZBE7s5kh2NOtb3kURadqbd0KJxCp0mnujbUqI39rYhQKc9S/X
iRqY0Q9ABYcAWVkhyApK7fh45xpn/fj0HozQOduhZ6nOh5vEZY//kxfBY1Kcztx6
Vv2JJ+NDos0d31p1kSy0tNHK8qgTuQHCBMIGsy+dZWRM5h5w0QTJP0Q3fLFC5Csx
TLZ36ir72E0mygBPD1O7BRDi+lwuWNbO95Aa9S8EnaPdQBOAjOo=
=rZ8B
-----END PGP SIGNATURE-----