#1148834 swift: [OSSA-2026-041] PUT TempURL plus X-Copy-From reads another container (CVE-2026-97149)

Package:
src:swift
Source:
src:swift
Submitter:
Salvatore Bonaccorso
Date:
2026-10-02 15:25:05 UTC
Severity:
normal
Tags:
#1148834#5
Date:
2026-09-24 07:29:25 UTC
From:
To:
Hi,

The following vulnerability was published for swift.

CVE-2026-97149[0]:
| In OpenStack Swift before 2.38.2, the tempurl middleware does not
| reject the X-Copy-From header on PUT requests. A TempURL signature
| only covers the method, expiry, and path, and thus the list of
| disallowed headers is the only defense against a signed PUT request
| changing what the request does. An attacker holding a PUT TempURL
| for a single object can add an X-Copy-From header naming any object
| in the same account; the copy middleware copies that object to the
| destination, and the attacker then reads the victim's data back with
| a GET TempURL for the destination object. Copies across account
| boundaries are rejected. Only deployments using the shipped default
| proxy pipeline (tempurl and copy middleware) with account-level
| TempURL keys are affected.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-97149
https://www.cve.org/CVERecord?id=CVE-2026-97149
[1] https://bugs.launchpad.net/swift/+bug/2166876

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1148834#8
Date:
2026-09-24 12:00:28 UTC
From:
To:
Hello,

Bug #1148834 in swift reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/swift/-/commit/de6ac41e6866153052d24c8facd603f04139d27e
OSSA-2026-041 / CVE-2026-97149: TempURL PUT with an X-Copy-From header
reads another container (cross-container information disclosure).
Applied upstream patch:
- CVE-2026-97149_OSSA-2026-041-stable-2026.2.patch
  ("tempurl: Disallow X-Copy-From on tempurl requests")
(Closes: #1148834).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148834

#1148834#15
Date:
2026-09-24 12:34:24 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
swift, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1148834@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated swift package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 24 Sep 2026 13:24:52 +0200
Source: swift
Architecture: source
Version: 2.38.1-3
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1148834
Changes:
 swift (2.38.1-3) unstable; urgency=high
 .
   * OSSA-2026-041 / CVE-2026-97149: TempURL PUT with an X-Copy-From
     header reads another container (cross-container information
     disclosure). Applied upstream patch:
     - CVE-2026-97149_OSSA-2026-041-stable-2026.2.patch
       ("tempurl: Disallow X-Copy-From on tempurl requests")
     (Closes: #1148834).
Checksums-Sha1:
 22f2161c3e81c74ba06e2a0ad076a5e0d05e5adb 3193 swift_2.38.1-3.dsc
 1152618fa1286e94d8e88025334ae6626a22fc1d 34892 swift_2.38.1-3.debian.tar.xz
 96c5deb76c0aebaed4a392a96d50949a63c40c10 14073 swift_2.38.1-3_amd64.buildinfo
Checksums-Sha256:
 36e2d3860cfe4acb08961ede776638808cf89aefca8dd39bec85d1d174d1db0c 3193 swift_2.38.1-3.dsc
 f0755df787bd8b0fa9240f8b3112fb8a53266792d58db67ff0021ec4a9530e30 34892 swift_2.38.1-3.debian.tar.xz
 afd22559761831f037a74b8bc2fc46f62be0e5fd55d7cca3acef585417dc6a68 14073 swift_2.38.1-3_amd64.buildinfo
Files:
 a8213b919408a9a1624910cdb59e8324 3193 net optional swift_2.38.1-3.dsc
 dc472b3d42be1b45a3c51c6ceac1cfd3 34892 net optional swift_2.38.1-3.debian.tar.xz
 6083158415a8f3999e93b8c2ae86fdc2 14073 net optional swift_2.38.1-3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmq1EjoACgkQ1BatFaxr
Q/6TdRAAmazPIwggw/IwEunfqg4MQbVuH2k/yc4aeGgmDGskzfdTPrLoLklzqKha
uFZsH0bta1FhrKkzczvJZE7OdUdSIe/E8vuw7N0/JOlFuF1OvfBi7zA1UN9fBm+7
u2FQYIHC5R7dQVb09Z3y2dNF5OXKfNcQC+f+lUYAMHNzjZow8nUEwtMcrUmEk9in
2Can2Gso8Nb2L9p1XrZ4ozbc5AdzGGkBIShwc/3Ii1rSh5XGSiZG9nbO1vLWW+RW
YvBy/7h/wP9ecuHJd0jAeF9cimfEWo9/3bv+rDWleb7DNuwnf4b3bH+6DZFONAKm
5yqdOJw0tFsgB+XHb/95Br5NfDlkl9uteBppDscV8EqhH36NLe9CyJhzpgQX/ew4
dyFAgUpyMbsRKjY8wJDkgYEkCDuD1F6QbCjkAfPxdW4tH9xn4MswsQjQ8+J5ZBtU
52RIfIDmmeNaC5ks+PQyCPKt1NdFkPhMn+F3GfAMioarB4BAIXxog3905UneoQpT
Cx+aQz+kcKd+XsnisMcYwYibcHI4JDcRNtm7R1eXY98eI+MRiyK9EKkznTpqQXKq
MuSiSPu6f5r+lBQmdFB/Vkh6rV48l0eTCgaRYdTVC1prltoLwYjVmmO4HIDUndk/
nP5xOHq3tA6Jjp03T5AdiSuZsnQ7Mu/J9Mg8ZghiRdzB4OYJAVU=
=XNqS
-----END PGP SIGNATURE-----

#1148834#18
Date:
2026-09-24 12:36:07 UTC
From:
To:
Hello,

Bug #1148834 in swift reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/swift/-/commit/37baebcb58c1570d17044fd425f5e5444d8617a4
  * OSSA-2026-041 / CVE-2026-97149: TempURL PUT with an X-Copy-From
    header reads another container (cross-container information
    disclosure). Applied upstream patch:
    - CVE-2026-97149_OSSA-2026-041-stable-2026.1.patch
      ("tempurl: Disallow X-Copy-From on tempurl requests")
    (Closes: #1148834).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148834

#1148834#25
Date:
2026-10-02 15:24:17 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
swift, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1148834@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated swift package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 24 Sep 2026 15:30:56 +0200
Source: swift
Architecture: source
Version: 2.35.1-0+deb13u4
Distribution: trixie-security
Urgency: medium
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1148834
Changes:
 swift (2.35.1-0+deb13u4) trixie-security; urgency=medium
 .
   * CVE-2026-97149 / OSSA-2026-041: TempURL PUT with an X-Copy-From
     header reads another container (cross-container information
     disclosure). Applied upstream patch:
     - CVE-2026-97149_OSSA-2026-041_tempurl_Disallow_X-Copy-From_on_tem....patch
       ("tempurl: Disallow X-Copy-From on tempurl requests")
     (Closes: #1148834).
   * Blacklist two more non-deterministic tests of the same family as the
     already blacklisted test_operations_timing_stats_with_incr_timeout:
     - test_operations_timing_stats_with_get_timeout
     - test_operations_timing_stats_with_set_timeout
Checksums-Sha1:
 c5db6eb041e1c01d65489377298ceb2d0d43c1e4 3165 swift_2.35.1-0+deb13u4.dsc
 5dc7039ecfd608a05ec987bfe49cc2fb6f587148 2706568 swift_2.35.1.orig.tar.xz
 bef424f0edf1e57067adab3009a42834e6a9adb0 39080 swift_2.35.1-0+deb13u4.debian.tar.xz
 f62d336aab207bba0f0abc0f1f97cbfbd4fb2875 14989 swift_2.35.1-0+deb13u4_amd64.buildinfo
Checksums-Sha256:
 d96c963dd70dfedbb21f696c39c4c10414a03bcce0f8346089783179666081a8 3165 swift_2.35.1-0+deb13u4.dsc
 ee2bba0d77ce5bccc04db93d531ddd65ee092a1ce1070b0995f1ca8f7a3a5beb 2706568 swift_2.35.1.orig.tar.xz
 c512aec30fcd200f29213e2a9f1658c4af27abb11ab46716069881f9155a0f13 39080 swift_2.35.1-0+deb13u4.debian.tar.xz
 6725c80b8a10ded01d86c8566ae58c637b688726506489762c8ea0931bbac341 14989 swift_2.35.1-0+deb13u4_amd64.buildinfo
Files:
 31cc64ba1adf9d2b031a58453ea60b3b 3165 net optional swift_2.35.1-0+deb13u4.dsc
 0fe9e0f72d050292fb9182633c9462af 2706568 net optional swift_2.35.1.orig.tar.xz
 501c7c727b91d7edb053e0b7e92eda70 39080 net optional swift_2.35.1-0+deb13u4.debian.tar.xz
 dd5eccaeab456c1e21699609a4b64adb 14989 net optional swift_2.35.1-0+deb13u4_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmq1lQYACgkQ1BatFaxr
Q/4bpQ//c8SO1BmfFCtuhJOYMpAYtJwvYsJYi8vExSGQW3FpJ/xyVYbI0XLq+YBw
zSRTac1PWIFCBKOTd6k/qXywkqLAV+74Mladnrur/OiPWCzK3XgBA9ILrhmD13vS
WB26tb9gR0jfBnmm8DHf9BN12jPDuvGqwsBPYiX/yPRC0YyHbsRVJD0/2CGG8/2z
QtCg1JCv3jJLE83mFOj3o2cXm1Qlg8mjV6qF+aLgmmS7iqA44mU19netbWbf066L
lLMSGCrGF0e7p+cziJiiNHeKAzU0ZrwROR4uUhhtmVxOdmjFXcjYPj0kdOObmTp5
KhmT8WZY5018UW6nXk4DTHSsRLrCb6nUklKMw4CZDmNl/r7DBxjq6bQ/+/ifDCmf
Ip28shU87OUicUdYCaLqZGzktSooc/JCMubBOS7pFl9DEiz7GmQnIaLJCQzsswMk
/G6/xSMqgHngBeGjqLCMZHIGn2kfBLTLbt6NI8usl9j/1CXN+ieuc+90aIp32y2e
zZaPPEjBGgt6dyku8l4ui+Nc5fwT0GSKyrQfuc3dAdTOEyjfO2/IAEG05b44paxG
n7AxT+VTKY+oDSncSN/TN31KVedJ67MyZIxrFFrLP5PiamgEwrLIervlsYLe7jUZ
gKq3rg1OZSKa/mVF2himI7/qdZwHRQw4a9btgDRB5oyhcaHctY4=
=oDwu
-----END PGP SIGNATURE-----