#1144879 OSSA-2026-036: cross-project alarm enumeration

Package:
src:aodh
Source:
src:aodh
Submitter:
Thomas Goirand
Date:
2026-08-21 08:21:00 UTC
Severity:
normal
Tags:
#1144879#5
Date:
2026-08-19 19:06:53 UTC
From:
To:
As per upstream announce:
https://security.openstack.org/ossa/OSSA-2026-036.html


Date:
    August 19, 2026
CVE:
    CVE-2026-pending

Affects:
    Aodh: >=10.0.0 <20.0.1, ==21.0.0, ==22.0.0
    Watcher: >=4.0.0 <14.1.2, >=15.0.0 <15.1.2, >=16.0.0 <16.0.2

Description:

Chen YuXiang of the Institute of Computing Technology, Chinese Academy of
Sciences reported that OpenStack Aodh does not enforce project scope on the
alarm listing API when the all_projects query parameter is supplied with a
false value. A non-admin user holding only the reader role can list alarms
belonging to other projects, optionally targeting a specific project, exposing
alarm metadata such as webhook action URLs, signal endpoints, and project
identifiers. All Aodh deployments are affected.

The same reporter found that OpenStack Watcher does not apply authorization to
its webhook trigger endpoint. Any authenticated user who learns an audit’s
webhook URL, for example from the Aodh alarm metadata leaked above, can start
an EVENT audit and its associated action plan regardless of their own project
or role. All Watcher deployments are affected.

Patches:
https://review.opendev.org/1001503 (2025.1/epoxy (aodh))
https://review.opendev.org/1001509 (2025.1/epoxy (watcher))
https://review.opendev.org/1001502 (2025.2/flamingo (aodh))
https://review.opendev.org/1001508 (2025.2/flamingo (watcher))
https://review.opendev.org/1001501 (2026.1/gazpacho (aodh))
https://review.opendev.org/1001507 (2026.1/gazpacho (watcher))
https://review.opendev.org/1001500 (2026.2/hibiscus (development) (aodh))
https://review.opendev.org/1001505 (2026.2/hibiscus (development) (watcher))

Credits:
    Chen YuXiang from Institute of Computing Technology, Chinese Academy
of Sciences

References:
https://launchpad.net/bugs/2161276
https://launchpad.net/bugs/2161771
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending

Notes:
    A CVE identifier was requested from MITRE for the aodh vulnerability on
2026-08-03. The CVE will be added to this advisory by errata once assigned.

#1144879#8
Date:
2026-08-19 19:47:15 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/4d789b90c510a3b307eb51a16f2f3b41d47523b9
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-03X: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879

#1144879#13
Date:
2026-08-19 19:48:35 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/14394ae17f71b082e377d52c0ca85ae36bc44f0e
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879

#1144879#16
Date:
2026-08-19 19:49:37 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/6f1b305736cd0479566ba1b0cd847ae575e68522
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879

#1144879#19
Date:
2026-08-19 19:50:33 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/55d0ed2c02f704414497fa9497ffb23f6e69c624
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879

#1144879#22
Date:
2026-08-19 20:06:31 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/59004027185a6cf3fd1a977fbe25a724f41ecb89
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879

#1144879#25
Date:
2026-08-19 20:08:54 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/8060a3e724ee38434e9c4a8ca02220b27e2c29b4
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879

#1144879#28
Date:
2026-08-19 20:09:42 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/16ac30ff691c87edcdda6387daa85c1897c09329
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879

#1144879#31
Date:
2026-08-19 20:10:53 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/ecc9aacc731c43f79e4f1732198716a28a0d565a
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879

#1144879#40
Date:
2026-08-21 08:02:12 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/f75635916b4a82ef228e26a55be12a6110ef6520
------------------------------------------------------------------------
* CVE-2026-76878 / OSSA-2026-03X: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879

#1144879#43
Date:
2026-08-21 08:02:35 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/bf70f41c2fe696c3f77528f5b4c7d88286955cfc
------------------------------------------------------------------------
* CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879

#1144879#46
Date:
2026-08-21 08:03:23 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/834a4c76e9a2eab4b24f142e95c4da2d2492d7ff
------------------------------------------------------------------------
* CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879

#1144879#49
Date:
2026-08-21 08:04:03 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/30156bfdfc26b52508040071775e264bca8ffef2
------------------------------------------------------------------------
* CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879

#1144879#52
Date:
2026-08-21 08:06:12 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/dd7dad460101fe59ec054c2282daab5fad3627a1
------------------------------------------------------------------------
* CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879

#1144879#55
Date:
2026-08-21 08:06:50 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/0e38cd1e64d306560871ff47d745fe80545d69d4
------------------------------------------------------------------------
* CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879

#1144879#58
Date:
2026-08-21 08:08:14 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/1655783ff5f99bbcf4ec75cda0cd8ab7253bf64c
------------------------------------------------------------------------
* CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879

#1144879#61
Date:
2026-08-21 08:09:20 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/0f6bf58aa69cbd8405bfe7646e97c6bde2a46570
------------------------------------------------------------------------
* CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879

#1144879#64
Date:
2026-08-21 08:10:42 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/676d77b113265abc78b717952d20f79377b08d95
------------------------------------------------------------------------
* CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879

#1144879#67
Date:
2026-08-21 08:12:26 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/a07bc19294568ba5ecc2b5b250288dc472a8fe78
------------------------------------------------------------------------
* CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879

#1144879#70
Date:
2026-08-21 08:18:24 UTC
From:
To:
Hello,

Bug #1144879 in aodh reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/aodh/-/commit/a942af5aa2fe12d2f9367752ff508c16d6a2ea8b
------------------------------------------------------------------------
* CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project
    scope when the all_projects query parameter is present with a false value.
    A non-admin project reader can list alarms belonging to other projects by
    passing all_projects=false in a list query, optionally combined with a
    foreign project_id to target a specific project. Leaked alarm data includes
    trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
    upstream patch: "Fix all_projects=false bypass project scope"
    (Closes: #1144879).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144879