#1148897 CVE-2026-97404 OSSA-2026-042: Zaqar empty URL-Signature header bypasses authentication

Package:
src:zaqar
Source:
src:zaqar
Submitter:
Thomas Goirand
Date:
2026-09-24 19:20:56 UTC
Severity:
normal
Tags:
#1148897#5
Date:
2026-09-24 18:37:44 UTC
From:
To:
As per upstream announce at:
https://security.openstack.org/ossa/OSSA-2026-042.html


=======================================================================
OSSA-2026-042: Zaqar empty URL-Signature header bypasses authentication
=======================================================================

:Date: September 24, 2026
:CVE: CVE-2026-97404


Affects
~~~~~~~
- Zaqar: >=1.0.0 <20.1.2, >=21.0.0 <21.0.2, >=22.0.0 <22.0.2


Description
~~~~~~~~~~~
pple, an independent security researcher, reported that Zaqar's
WSGI transport mishandles an empty URL-Signature header: a request
carrying the header with an empty value bypasses both Keystone
authentication and pre-signed URL verification. An unauthenticated
remote attacker who knows a target project's UUID can then read,
enumerate, create, and delete that project's queues, messages,
claims, and subscriptions. By additionally claiming an
administrative role, the attacker may also perform administrative
operations, such as managing pools and flavors in admin_mode
deployments. Only deployments using the WSGI transport with an
authentication strategy configured are affected; the websocket
transport is not affected.



Patches
~~~~~~~
- https://review.opendev.org/1007162 (2025.1/epoxy)
- https://review.opendev.org/1007161 (2025.2/flamingo)
- https://review.opendev.org/1007160 (2026.1/gazpacho)
- https://review.opendev.org/1007159 (2026.2/hibiscus)
- https://review.opendev.org/1007158 (2027.1/indri (development))


Credits
~~~~~~~
- pple from Independent (CVE-2026-97404)


References
~~~~~~~~~~
- https://launchpad.net/bugs/2164987
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-97404


Notes
~~~~~
- This issue is distinct from the EXTRA-SPEC header bypass in
  OSSA-2026-029; the fix for that issue removed the EXTRA-SPEC branch
  but left the empty-value handling of the URL-Signature header
  untouched.

#1148897#10
Date:
2026-09-24 19:00:35 UTC
From:
To:
Hello,

Bug #1148897 in zaqar reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/zaqar/-/commit/1bb9e6439031cf8c1dc67795b056650ccfc69658
------------------------------------------------------------------------
* CVE-2026-97404 / OSSA-2026-042: Zaqar empty URL-Signature header
    bypasses authentication. Applied upstream patch "Fix authentication
    bypass by empty URL-Signature". (Closes: #1148897):
    - CVE-2026-97404_OSSA-2026-042_Fix_authentication_bypass_by_empty_....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148897

#1148897#17
Date:
2026-09-24 19:09:09 UTC
From:
To:
Hello,

Bug #1148897 in zaqar reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/zaqar/-/commit/2d12206dbec8f9b8eef0b6af20718de2e2d29c83
------------------------------------------------------------------------
* CVE-2026-97404 / OSSA-2026-042: Zaqar empty URL-Signature header
    bypasses authentication. Applied upstream patch "Fix authentication
    bypass by empty URL-Signature". (Closes: #1148897):
    - CVE-2026-97404_OSSA-2026-042_Fix_authentication_bypass_by_empty_....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148897

#1148897#20
Date:
2026-09-24 19:11:45 UTC
From:
To:
Hello,

Bug #1148897 in zaqar reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/zaqar/-/commit/7baa54e01baeabb0fff32c030f646cb4dc022d46
------------------------------------------------------------------------
* CVE-2026-97404 / OSSA-2026-042: Zaqar empty URL-Signature header
    bypasses authentication. Applied upstream patch "Fix authentication
    bypass by empty URL-Signature". (Closes: #1148897):
    - CVE-2026-97404_OSSA-2026-042_Fix_authentication_bypass_by_empty_....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148897

#1148897#23
Date:
2026-09-24 19:13:18 UTC
From:
To:
Hello,

Bug #1148897 in zaqar reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/zaqar/-/commit/7bc4cc2ad31e54f50a036308f3b4b47866fe6251
------------------------------------------------------------------------
* CVE-2026-97404 / OSSA-2026-042: Zaqar empty URL-Signature header
    bypasses authentication. Applied upstream patch "Fix authentication
    bypass by empty URL-Signature". (Closes: #1148897):
    - CVE-2026-97404_OSSA-2026-042_Fix_authentication_bypass_by_empty_....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148897

#1148897#28
Date:
2026-09-24 19:19:07 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
zaqar, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1148897@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated zaqar package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 24 Sep 2026 20:56:40 +0200
Source: zaqar
Architecture: source
Version: 23.0.0~rc1-3
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1148897
Changes:
 zaqar (23.0.0~rc1-3) unstable; urgency=high
 .
   * CVE-2026-97404 / OSSA-2026-042: Zaqar empty URL-Signature header
     bypasses authentication. Applied upstream patch "Fix authentication
     bypass by empty URL-Signature". (Closes: #1148897):
     - CVE-2026-97404_OSSA-2026-042_Fix_authentication_bypass_by_empty_....patch
Checksums-Sha1:
 b6c2e25ae8d19e4635875f6bc1d0b29c238469ee 3177 zaqar_23.0.0~rc1-3.dsc
 5f5296cc5f1812f2ef1366578d7fab475ce7a58a 10964 zaqar_23.0.0~rc1-3.debian.tar.xz
 eaa35eedfc4f71041579c5e264debe84c5da4199 16529 zaqar_23.0.0~rc1-3_amd64.buildinfo
Checksums-Sha256:
 a457bab8c3e047b7a8cd4f02b374fb39d0723327d065409cc64d17cc5f7af2e6 3177 zaqar_23.0.0~rc1-3.dsc
 100214c5ec0d3f35f46244e3c8be363384f4fd24ee1afed1f793b05603629230 10964 zaqar_23.0.0~rc1-3.debian.tar.xz
 35e309f946820f6a3bc25c8de85cf09db35887cdd2fd512b01626fa54a95b854 16529 zaqar_23.0.0~rc1-3_amd64.buildinfo
Files:
 f23f60cc856b3e658355a82409ec822f 3177 net optional zaqar_23.0.0~rc1-3.dsc
 b763e86d5ba777d7988ad4bd432d9e56 10964 net optional zaqar_23.0.0~rc1-3.debian.tar.xz
 a642b931bf6fd6b3e3fc129b4a0b370d 16529 net optional zaqar_23.0.0~rc1-3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmq1c1gACgkQ1BatFaxr
Q/7fwg//TzVcvSR3mUlb+qSWY4rV3lcZUJguyJ4RA5JPdliV+97kdUkjA7xQ8N0z
x+B5Sdij9SyQ7iSXSMsi/Jfu7L4BeJWmnd9EN3P0X8Y4nS00La587J4y39HhSONU
dl5/RjrTczOV8olb6LKR5To16nE64jEbNWNHOYaK1WTNSuzLo0yq0ew90GYuViIf
DK/oNDckv/m1XjyvJLKlDg4Bh6gw8iv56aStznDfDkoF64MK4Hy7let/9eQ8CoYK
Iqdm9VBc00y1OVGBIMnFUny9BabK7mxG3Pd66RJrZDSZS/SaEYeptR77BrNPW7Ky
9zMKE7Z5ys5B4tktJ1lAIx88g18truaNp8GdKXunzGIxoDoiMiBSiLC6bBbA6eG3
NfxkoKRVGpKfJiUH482E5lE+qwKeRoQL8i6qajSoJv4w6uzVc5J3EyUOAtd4dfMK
v/Xnzu8Tdg0JTnPuG+t+92xXroYTkmfIHIpor3Xptjcgu+XKTxoRgl+b5+DV4l/J
KCjGohNHTAKhS/IpCBb4zUk4dOHYR4cxzlwMmdtUTa5FgCJrfdhi3fi7ufBSyNkT
t6+zqXM+aa6F/W8XSW3IXqOzBRHz5/iPdKNe1/ytYu7hSoRdYBFViIY90lJYa/ju
bKjd9lLLuiqC1QHsLZEUfhx55Rd6Q/uGm4zR4Nq0PKTCJ3Vo56c=
=RSKR
-----END PGP SIGNATURE-----

#1148897#31
Date:
2026-09-24 19:18:09 UTC
From:
To:
Hello,

Bug #1148897 in zaqar reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/zaqar/-/commit/e660e30e9c77f1870af2fda51af8e59397009869
------------------------------------------------------------------------
* CVE-2026-97404 / OSSA-2026-042: Zaqar empty URL-Signature header
    bypasses authentication. Applied upstream patch "Fix authentication
    bypass by empty URL-Signature". (Closes: #1148897):
    - CVE-2026-97404_OSSA-2026-042_Fix_authentication_bypass_by_empty_....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148897

#1148897#36
Date:
2026-09-24 19:19:33 UTC
From:
To:
Hello,

Bug #1148897 in zaqar reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/zaqar/-/commit/2969d259bfe77d3ebe6925b492e448a69500664a
------------------------------------------------------------------------
* CVE-2026-97404 / OSSA-2026-042: Zaqar empty URL-Signature header
    bypasses authentication. Applied upstream patch "Fix authentication
    bypass by empty URL-Signature". (Closes: #1148897):
    - CVE-2026-97404_OSSA-2026-042_Fix_authentication_bypass_by_empty_....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148897

#1148897#39
Date:
2026-09-24 19:20:16 UTC
From:
To:
Hello,

Bug #1148897 in zaqar reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/zaqar/-/commit/41c026eaf41bc592a9af1a7a41e39d5c3ec1e44f
------------------------------------------------------------------------
* CVE-2026-97404 / OSSA-2026-042: Zaqar empty URL-Signature header
    bypasses authentication. Applied upstream patch "Fix authentication
    bypass by empty URL-Signature". (Closes: #1148897):
    - CVE-2026-97404_OSSA-2026-042_Fix_authentication_bypass_by_empty_....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148897