- Package:
- src:keystone
- Source:
- src:keystone
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-09-02 21:19:10 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for keystone. CVE-2026-80183[0]: | In OpenStack Keystone before 29.0.3, any authenticated user holding | role:reader on any project can list every project-scoped role | assignment under any domain by passing a domain ID as | scope.project.id with include_subtree to the GET | /v3/role_assignments endpoint. The domain's project record has | domain_id=null, causing the policy domain_id check to pass for any | caller. With include_names, the response discloses the names and | home-domain IDs of every user, group, project, and role involved. | The literal "default" domain ID works against any deployment created | with keystone-manage bootstrap. An attacker can harvest domain IDs | from the response and repeat the query to map role assignments | across the entire cloud. This is caused by misuse of "None" in | list_role_assignments_for_tree. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-80183 https://www.cve.org/CVERecord?id=CVE-2026-80183 [1] https://launchpad.net/bugs/2154645 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hello, Bug #1145816 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/eaddd6cd02e504f989241a05e0c2c3f14e7f31f1 ------------------------------------------------------------------------ * CVE-2026-80183 / OSSN-2026-0XXX: any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in list_role_assignments_for_tree. Applied upstream patch (Closes: #1145816): - CVE-2026-80183_Prevent_unauthorized_project-scoped_assignment_list.patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1145816
Hello, Bug #1145816 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/106a581eae644e4ed602e228ea9ceffd1a199031 ------------------------------------------------------------------------ * CVE-2026-80183 / OSSN-2026-0XXX: any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in list_role_assignments_for_tree. Applied upstream patch (Closes: #1145816): - CVE-2026-80183_Prevent_unauthorized_project-scoped_assignment_list.patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1145816
Hello, Bug #1145816 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/27a7492e7318ae5dcff91a3a2afe9ca0a9fa891c ------------------------------------------------------------------------ * CVE-2026-80183 / OSSN-2026-0XXX: any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in list_role_assignments_for_tree. Applied upstream patch (Closes: #1145816): - CVE-2026-80183_Prevent_unauthorized_project-scoped_assignment_list.patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1145816
Hello, Bug #1145816 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/aa908ac2059fd57f4f73cb0b1dcd920821b9359e ------------------------------------------------------------------------ * CVE-2026-80183 / OSSN-2026-0XXX: any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in list_role_assignments_for_tree. Applied upstream patch (Closes: #1145816): - CVE-2026-80183_Prevent_unauthorized_project-scoped_assignment_list.patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1145816
We believe that the bug you reported is fixed in the latest version of
keystone, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1145816@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated keystone package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 27 Aug 2026 20:05:41 +0200
Source: keystone
Architecture: source
Version: 2:29.0.2-2
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1145816
Changes:
keystone (2:29.0.2-2) unstable; urgency=medium
.
* CVE-2026-80183 / OSSN-2026-0XXX: any authenticated user holding role:reader
on any project can list every project-scoped role assignment under any
domain by passing a domain ID as scope.project.id with include_subtree to
the GET /v3/role_assignments endpoint. The domain's project record has
domain_id=null, causing the policy domain_id check to pass for any caller.
With include_names, the response discloses the names and home-domain IDs of
every user, group, project, and role involved. The literal "default" domain
ID works against any deployment created with keystone-manage bootstrap. An
attacker can harvest domain IDs from the response and repeat the query to
map role assignments across the entire cloud. This is caused by misuse of
"None" in list_role_assignments_for_tree.
Applied upstream patch (Closes: #1145816):
- CVE-2026-80183_Prevent_unauthorized_project-scoped_assignment_list.patch
Checksums-Sha1:
9a83e651cb6f894ab37b46e4701860c8ca3bb21f 3458 keystone_29.0.2-2.dsc
c164147be6e03d79e462621eae6708fe782ceaeb 64044 keystone_29.0.2-2.debian.tar.xz
d0030c4f2531e1d582a570a1f1ef218d080a0fcf 17314 keystone_29.0.2-2_amd64.buildinfo
Checksums-Sha256:
1c465331fa1554b51df80dfff3276ee81820dbcd8834509e130285be0a2aaf2e 3458 keystone_29.0.2-2.dsc
77d04de4bdc2c3aafe2803f8fdc4952c403f8fbdf5d3f51f249785f67486b487 64044 keystone_29.0.2-2.debian.tar.xz
c8fc7c4ebf6f941ea26ee4566e282cebd98057e68d58ca4b3ae7d0a7d7b863fa 17314 keystone_29.0.2-2_amd64.buildinfo
Files:
a473c414ef04aec3c076b5cb2e06b85d 3458 net optional keystone_29.0.2-2.dsc
3f799fcf20aa899a1aa4cd76f04b85ec 64044 net optional keystone_29.0.2-2.debian.tar.xz
2b288ec626eb538472a8e8ffd96c6c90 17314 net optional keystone_29.0.2-2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqQgDIACgkQ1BatFaxr
Q/4H8g/+NWeLwJ8c7uo73v6oXY6e8WJSpiD6545v8foQurI+UlkfqvpAiXOgdbwh
2viYHMiBUgnKi+vHImOEPffVxKuZM+j9MGqZtLkuav7VstOGBOKw48TmdBqbE4JK
MoQ0gguVxod5MJWAxtgN8yWaTihcGVGOUJ7lQhlSgYhuKNlBhEEgFbFx6M/6u2mj
PfKy06SHQLLann38inF+cbQ+uCzolrogYvV3T/dx3UU4q8By5d1rxsiZh6uIZFSw
J7gw7cowY5+FAYp8oZmLT3RGfoi/PN1FrurY8ICvwKaikYpNbvb1ZCW2/F/rb/J0
eD/EoTaPfujP25og3gMKRco419d7vPkVTsQaRVD3sjd5qaN+Z3kCvRiJuG2HyOcL
D7iC1AuWMx5vP7SZXYth1QQaaK75Er02G3gtwuJiyPGe/uGJV1EAR0GDxnrTIvBe
kxWFN2zfLm0oqpzBdj/FSfXhpL4kwvg4UvJqnmFuy7PaGHQlX56stWk0JQpyIoi9
ZVdXQ1cdoFeDzqXhUD+41I2B7+dR/H7yBV4i8qjWzy2kB6hOzXAwuMWC+6sP7HNh
cJnTLv6KAgZ4XpNB6VBaKQmttfnn8HrqGRsxeswr1oHQ8Bx+rAQoebEaR0NdUVhW
AaB1c1uPcwTG/xSeP98K5lXQkENYNf9kirrmOOYquXcyIwOcZ08=
=ry5J
-----END PGP SIGNATURE-----
Hello, Bug #1145816 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/80537ae6c1b980eb368a661b3a5d34dab3f7c814 ------------------------------------------------------------------------ * CVE-2026-80183 / OSSN-2026-0XXX: any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in list_role_assignments_for_tree. Applied upstream patch (Closes: #1145816): - CVE-2026-80183_Prevent_unauthorized_project-scoped_assignment_list.patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1145816
Hello, Bug #1145816 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/d7bd5794a5df243cbf991712e9ed60e45ac9b03a ------------------------------------------------------------------------ * CVE-2026-80183 / OSSN-2026-0XXX: any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in list_role_assignments_for_tree. Applied upstream patch (Closes: #1145816): - CVE-2026-80183_Prevent_unauthorized_project-scoped_assignment_list.patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1145816
We believe that the bug you reported is fixed in the latest version of
keystone, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1145816@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated keystone package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 28 Aug 2026 09:41:35 +0200
Source: keystone
Architecture: source
Version: 2:27.0.0-3+deb13u5
Distribution: trixie-security
Urgency: medium
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1145669 1145816
Changes:
keystone (2:27.0.0-3+deb13u5) trixie-security; urgency=medium
.
* CVE-2026-80184: Delegation bypass in trust, OAuth1, and application
credential operations.
* CVE-2026-80182: Tokens obtained via application credential or EC2
credential authentication can escape their intended project scope through
token-method reauthentication. An application-credential token scoped to
one project can be exchanged via POST /v3/auth/tokens with no explicit
scope, causing Keystone to issue a new token scoped to the owner's default
project. For EC2-derived tokens the bypass is broader: because they carry
no delegation markers, they can rescope to any project where the underlying
user has role assignments.
* Add new patches (Closes: #1145669):
- CVE-2026-80182_CVE-2026-80184_1_Block_app_credential_token_resco....patch
- CVE-2026-80182_CVE-2026-80184_2_auth_encode_ec2credential_and_oa....patch
- CVE-2026-80182_CVE-2026-80184_3_trusts_oauth1_app-creds_reject_d....patch
- CVE-2026-80182_CVE-2026-80184_4_auth_reject_delegated_tokens_fro....patch
* CVE-2026-80183 / OSSN-2026-0XXX: any authenticated user holding role:reader
on any project can list every project-scoped role assignment under any
domain by passing a domain ID as scope.project.id with include_subtree to
the GET /v3/role_assignments endpoint. The domain's project record has
domain_id=null, causing the policy domain_id check to pass for any caller.
With include_names, the response discloses the names and home-domain IDs of
every user, group, project, and role involved. The literal "default" domain
ID works against any deployment created with keystone-manage bootstrap. An
attacker can harvest domain IDs from the response and repeat the query to
map role assignments across the entire cloud. This is caused by misuse of
"None" in list_role_assignments_for_tree.
Applied upstream patch (Closes: #1145816):
- CVE-2026-80183_Prevent_unauthorized_project-scoped_assignment_list.patch
Checksums-Sha1:
8b7fa7356687caf2018cc031b84437f216098b6f 3486 keystone_27.0.0-3+deb13u5.dsc
896a6f57c727fa62d0aec10d5c8844b40cc42bdb 1098444 keystone_27.0.0.orig.tar.xz
590937c413889aa118ec5e2dfa3d39a54af4ced6 81732 keystone_27.0.0-3+deb13u5.debian.tar.xz
d0acf734afd9fa9f74da92a47f411fd59c9bae47 18779 keystone_27.0.0-3+deb13u5_amd64.buildinfo
Checksums-Sha256:
597252e68249fbbe1266d0778c459408508b432f4e4d9bb33f33c3ac690c81a7 3486 keystone_27.0.0-3+deb13u5.dsc
223b27dc676dabd6c9d67e4409fe086f92b5d47bf71ee8c724c3e0d13f26d635 1098444 keystone_27.0.0.orig.tar.xz
b80c4e12d419b1cd19b7fbf31fc615854bf8dee95001bb59fa5c4e9a189b2656 81732 keystone_27.0.0-3+deb13u5.debian.tar.xz
3f48302bfafa73455f8cc84e85ca1120fc8a90a79d1f7e3cc23d48ece90aea89 18779 keystone_27.0.0-3+deb13u5_amd64.buildinfo
Files:
df7fd282803d1e8db8bed179433a4772 3486 net optional keystone_27.0.0-3+deb13u5.dsc
d8119041a4ba1c4545ab5dabe9ae65b9 1098444 net optional keystone_27.0.0.orig.tar.xz
abaf99efbe87784c9ab911f75ccb2e42 81732 net optional keystone_27.0.0-3+deb13u5.debian.tar.xz
e83a67b6056bcc9fa8be77219176f2cc 18779 net optional keystone_27.0.0-3+deb13u5_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqVMGAACgkQ1BatFaxr
Q/5Lfw//ekgssRChl7JfyUUhn5+CnrmSfYuGlYu+Yrl0KtSGo89HmXaS3Lq0u/Nx
ild5Ulxdj6A23HsW8s3huMafD+a93sUWogLDEDLPWwRo6gXtNo00kpr//DaOir2N
lcEU/ryPdTusHSTJfuhEGjF6g1BuBVz8KDrd8M3gfgosilqXG676Vo6BfIAsn5OP
bo8lt9xQRHC72dtgZkQB7C7ZzLFuyG8gm8+FO6wwqg+NCkLHe3RwVZ+9MawBi0tA
65lb8Atf/UXVrjfM/3dO7mYdKzxPsDHNHnUjdq7Q2dnupx4/WoRc6Vx2ZxJB5ZTC
3pn84FZx5bB7O2b1Ka0F2DmDmyqoIuFKSWDfpgls5mvS1GfG+YAeZrG1g1/H/7s7
Xv+xbRM1RV4wjMj61Hhbdt/fErsvHrJVa2u7vtYjc1o59F4+oL4NAg8zbiGdJ4Rf
W9iCNyS9tHlxnPbe/IvTAKDYQrIYY7J7s+ZBvUKkWzdz6gO37ihHJteIXIrSTCX6
aTrVFrSvm1o4kBPltClgslrgPm+1TxWn1J1b0QJyWyI3b+hDwBlN/SDo0vTk68hR
E9ZDXkqZ/4/hmx0BhAEwM9aut2BCZvejVVif8u8Ww1dOe5ItS9B0zmCjgfMV3Axl
iQ/R3gH+74ySnLu27hSX2TZkVqbYFSmjNdgUHvwh0w3c/v1zSco=
=Z+0F
-----END PGP SIGNATURE-----