#1148175 Command Injection (RCE) on Octavia amphora via API

Package:
src:octavia
Source:
src:octavia
Submitter:
Thomas Goirand
Date:
2026-09-18 04:43:02 UTC
Severity:
normal
Tags:
#1148175#5
Date:
2026-09-17 20:18:26 UTC
From:
To:
This has been reported on Launchpad here:

https://bugs.launchpad.net/octavia/+bug/2162101

and here:
https://bugs.launchpad.net/octavia/+bug/2162103

though the author probably haven't realized how grave the bug was.
In fact, we're talking about an RCE, since it's possible inject any type
of command into Haproxy.

The fixes are here:
https://review.opendev.org/q/Ia6affaafcaa8b22ec2e0c94b3c4007cccaae41ba
and here:
https://review.opendev.org/q/I23c3ca392233c7e8223a9a00b9ee07c6f4b63615

I'll backport these patches to all the versions of OpenStack I still support,
meaning from Bookworm (zed) to Unstable (Gazpacho).

Cheers,

Thomas Goirand (zigo)

#1148175#10
Date:
2026-09-17 20:34:02 UTC
From:
To:
Hello,

Bug #1148175 in octavia reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/octavia/-/commit/1377e79fc5cafdb03bebc5afe4c691a69d0e5d68
------------------------------------------------------------------------
* Octavia is vulnerable to an RCE in its amphora via the Octavia API.
    Added upstream patches (Closes: #1148175):
    - Fix_HAProxy_config_injection_via_tls_ciphers_field.patch
    - Fix_HAProxy_config_injection_via_L7_policy_redirect_URLs.patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148175

#1148175#15
Date:
2026-09-17 20:34:14 UTC
From:
To:
Hello,

Bug #1148175 in octavia reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/octavia/-/commit/7b58fc5e90a3dcc8703b16c436d4312851b6afc8
------------------------------------------------------------------------
* Octavia is vulnerable to an RCE in its amphora via the Octavia API.
    Added upstream patches (Closes: #1148175):
    - Fix_HAProxy_config_injection_via_tls_ciphers_field.patch
    - Fix_HAProxy_config_injection_via_L7_policy_redirect_URLs.patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148175

#1148175#20
Date:
2026-09-17 21:06:54 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
octavia, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1148175@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated octavia package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 17 Sep 2026 22:04:33 +0200
Source: octavia
Architecture: source
Version: 18.0.0-4
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1148175
Changes:
 octavia (18.0.0-4) unstable; urgency=medium
 .
   * Update debian/salsa-ci.yml.
   * Octavia is vulnerable to an RCE in its amphora via the Octavia API.
     Added upstream patches (Closes: #1148175):
     - Fix_HAProxy_config_injection_via_tls_ciphers_field.patch
     - Fix_HAProxy_config_injection_via_L7_policy_redirect_URLs.patch
   * Cleans better.
Checksums-Sha1:
 c8c75037c3aed54c8ad8ae58a27fa60480331698 4216 octavia_18.0.0-4.dsc
 1b428575830035688a16261b87ce642bb6c9dd1a 25212 octavia_18.0.0-4.debian.tar.xz
 b5c3a534681357ff413f36ebb80e38cca9f0c3a4 19860 octavia_18.0.0-4_amd64.buildinfo
Checksums-Sha256:
 6d5d3d9a5760c209427e60ec82ace9c9894dc161cd7d0f353de7f04886244023 4216 octavia_18.0.0-4.dsc
 35ee86c6c9f4d3bc145bd29b03cd9ecb3393396fd238c396bf00f2893bc7cff9 25212 octavia_18.0.0-4.debian.tar.xz
 7ab8d49720540a94b27d618c2a620c5f18197b41fedcf9028778ee9dc285ccd9 19860 octavia_18.0.0-4_amd64.buildinfo
Files:
 0c0736c03754a27311e6359f11b6a681 4216 net optional octavia_18.0.0-4.dsc
 9669501a86fddf407a3cf4b2d7d45568 25212 net optional octavia_18.0.0-4.debian.tar.xz
 b256a62aadabbd2e003cc52c7355a43a 19860 net optional octavia_18.0.0-4_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqsUXIACgkQ1BatFaxr
Q/4rmA/8CJ3Aoj7ByOyBG/tJShkPPVkjl5G+hSnFOHCjtohPK/AtXoH388px3QAM
1VuhxXQpXrFxpIYoz3S9R8QZ2BsCzAAY8L5ybj3F7XKBvEAOZdYA5ZPWGpgDMyHM
E4ji7IDZ/UUG8KpjV6oaNPqD0bZZna4hMzI3By0lHqrDFP1WG+y8ltxX41ooenhy
RZaiXVnZ2T3e/fexTCSbTNe+8ERwuWEe70Ze2zGnvcz8qzL6pwuk9hoXWGMLdCio
nFOCjpmL5dBOMkgd3kDFEm5mgdl3MJP1AMmoOcoE0iVuKg6LFNF+FAnUw5rWy+LM
9BtJyXc1CSyy8TrrUqQP565HmC87hn+YBGvIWrI4QFcIYdXXhR3+u2ajLfinWlIH
iIsZ1yqgo3b0np2nE8cwnitX44h+uU/r12MphmO4XwHnHWDiXCk17hGspTcr/Eta
wFgeooHS7kH7ohCjaLWrzwHraTYxDIpePe61ukyMDO05vzyn/ehhNBotrLl9C/lU
u+6x2vRvp5Q43pXDSJ89n84BlneUm3uoBw9wTBYWqpBbf6jkjRPB/sFodYsXgHTL
OZiCwS04tOyMP3ienAUQk4bzOfoj3B04/YGNHUcI7J2PstyerOr+L/3cGvynSNva
ja5g8zH8lRdcPrtDb2qcsKqi2ipwy8+WRy7HqIDQKu5FuEGa66Q=
=FkLh
-----END PGP SIGNATURE-----