#1150261 OSSA-2026-043 OpenStack Zaqar: Zaqar WebSocket project substitution allows cross-project queue access (CVE-2026-pending)

#1150261#5
Date:
2026-10-07 18:35:29 UTC
From:
To:
As per upstream announce here:
https://security.openstack.org/ossa/OSSA-2026-043.html

OSSA-2026-043: Zaqar WebSocket project substitution
allows cross-project queue access

Date: October 07, 2026
CVE: CVE-2026-pending


Affects
~~~~~~~
- Zaqar: >=1.0.0 <20.1.3, >=21.0.0 <21.0.3, >=22.0.0 <22.0.3, ==23.0.0


Description
~~~~~~~~~~~
Chen YuXiang from the Institute of Computing Technology, Chinese Academy
of Sciences reported a vulnerability in Zaqar's WebSocket transport. An
authenticated remote attacker who knows a target project's UUID may
substitute it in subsequent WebSocket frames to enumerate, inspect,
create, or delete queues belonging to that project. This may result in
unauthorized disclosure, modification, or loss of queue data. Only
deployments using the WebSocket transport with Keystone authentication
are affected.



Patches
~~~~~~~
- https://review.opendev.org/1009254 (2025.1/epoxy)
- https://review.opendev.org/1009253 (2025.2/flamingo)
- https://review.opendev.org/1009252 (2026.1/gazpacho)
- https://review.opendev.org/1009251 (2026.2/hibiscus)
- https://review.opendev.org/1009250 (2027.1/indri (development))


Credits
~~~~~~~
- Chen YuXiang from Institute of Computing Technology, Chinese Academy of Sciences


References
~~~~~~~~~~
- https://launchpad.net/bugs/2161402
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending


Notes
~~~~~
- A CVE identifier was requested from MITRE for this vulnerability on
  2026-10-06. The CVE will be added to this advisory by errata once
  assigned.

#1150261#8
Date:
2026-10-07 19:05:07 UTC
From:
To:
Hello,

Bug #1150261 in zaqar reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/zaqar/-/commit/9df0c38cf30a021b865de4183032c4cd3cd9fa52
------------------------------------------------------------------------
* CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution
    allows cross-project queue access. Applied upstream patch "Prohibit
    arbitrary project-id for websocket protocol access". (Closes: #1150261):
    - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150261

#1150261#13
Date:
2026-10-07 19:09:59 UTC
From:
To:
Hello,

Bug #1150261 in zaqar reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/zaqar/-/commit/34d0c073378166b33d4872fde8ddc5bfe0f03612
------------------------------------------------------------------------
* CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution
    allows cross-project queue access. Applied upstream patch "Prohibit
    arbitrary project-id for websocket protocol access". (Closes: #1150261):
    - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150261

#1150261#16
Date:
2026-10-07 19:10:00 UTC
From:
To:
Hello,

Bug #1150261 in zaqar reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/zaqar/-/commit/88571e409bb4e67f10c86e17a59e64f2a2d0742d
------------------------------------------------------------------------
* CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution
    allows cross-project queue access. Applied upstream patch "Prohibit
    arbitrary project-id for websocket protocol access". (Closes: #1150261):
    - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150261

#1150261#19
Date:
2026-10-07 19:12:08 UTC
From:
To:
Hello,

Bug #1150261 in zaqar reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/zaqar/-/commit/0fd73303f81faf400c1a0acdf836c3ec4d514116
------------------------------------------------------------------------
* CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution
    allows cross-project queue access. Applied upstream patch "Prohibit
    arbitrary project-id for websocket protocol access". (Closes: #1150261):
    - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150261

#1150261#22
Date:
2026-10-07 19:12:07 UTC
From:
To:
Hello,

Bug #1150261 in zaqar reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/zaqar/-/commit/891a271612b7dff0533d4e9c98957a754fd4dedc
------------------------------------------------------------------------
* CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution
    allows cross-project queue access. Applied upstream patch "Prohibit
    arbitrary project-id for websocket protocol access". (Closes: #1150261):
    - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150261

#1150261#25
Date:
2026-10-07 19:12:12 UTC
From:
To:
Hello,

Bug #1150261 in zaqar reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/zaqar/-/commit/2995ec847bf0ad9f8eab08faf7ec2fc287af51e2
------------------------------------------------------------------------
* CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution
    allows cross-project queue access. Applied upstream patch "Prohibit
    arbitrary project-id for websocket protocol access". (Closes: #1150261):
    - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150261

#1150261#28
Date:
2026-10-07 19:13:11 UTC
From:
To:
Hello,

Bug #1150261 in zaqar reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/zaqar/-/commit/03bb364283e79a84b604b62e191499d313327f9e
------------------------------------------------------------------------
* CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution
    allows cross-project queue access. Applied upstream patch "Prohibit
    arbitrary project-id for websocket protocol access". (Closes: #1150261):
    - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150261

#1150261#31
Date:
2026-10-07 19:13:52 UTC
From:
To:
Hello,

Bug #1150261 in zaqar reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/zaqar/-/commit/476bd9c9b3a93055e7f94b72fad18a3105261469
------------------------------------------------------------------------
* CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution
    allows cross-project queue access. Applied upstream patch "Prohibit
    arbitrary project-id for websocket protocol access". (Closes: #1150261):
    - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150261

#1150261#34
Date:
2026-10-07 19:15:52 UTC
From:
To:
Hello,

Bug #1150261 in zaqar reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/zaqar/-/commit/5fba4ff270e828552c0ffe8a98bf4c23baea90dd
------------------------------------------------------------------------
* CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution
    allows cross-project queue access. Applied upstream patch "Prohibit
    arbitrary project-id for websocket protocol access". (Closes: #1150261):
    - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150261

#1150261#39
Date:
2026-10-07 19:21:16 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
zaqar, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1150261@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated zaqar package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 07 Oct 2026 20:42:34 +0200
Source: zaqar
Architecture: source
Version: 23.0.0-2
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1150261
Changes:
 zaqar (23.0.0-2) unstable; urgency=high
 .
   * CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution
     allows cross-project queue access. Applied upstream patch "Prohibit
     arbitrary project-id for websocket protocol access". (Closes: #1150261):
     - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch
Checksums-Sha1:
 fb6ae9b3410128403536d74617ab40f80a941d2d 3149 zaqar_23.0.0-2.dsc
 9556f738c26e18c8a675de951be012c96b2fee79 11964 zaqar_23.0.0-2.debian.tar.xz
 9fb9d7daceba1f07dd4fbfd105b6fe9c57c6ecf2 16925 zaqar_23.0.0-2_amd64.buildinfo
Checksums-Sha256:
 d9886644a438db5e96f2667d5554ac6564014e1664f7770afb9a03c1934d144d 3149 zaqar_23.0.0-2.dsc
 71cdc1fb6d4c7f3784186e483e17181cd748afb016297cdae73ae07de004c3f6 11964 zaqar_23.0.0-2.debian.tar.xz
 7559b89f4f71c1b04fec398dfaf03102486d69d9329fa9b55427e41c9b150055 16925 zaqar_23.0.0-2_amd64.buildinfo
Files:
 2a96dee3efff507b2dea7e2a0cd42665 3149 net optional zaqar_23.0.0-2.dsc
 cda2aa8e8784d59eef2296ed0dd4c38b 11964 net optional zaqar_23.0.0-2.debian.tar.xz
 7a04cbed0bfa4278dcb78b733743a2ce 16925 net optional zaqar_23.0.0-2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmrGl+gACgkQ1BatFaxr
Q/5lpg//ZaJD/flUBE9abm0/G8WB6SmNHan4U8G3z4nfxMQsf7CkNbulv5RGZPx7
52u3MlVeXTASFhl/e4h9FhmQs6Dw/1Z/Dr7Nmd+WN9PJuXF2z3wTOq/edx42OWto
ysouRS3c9QKNdcMzfjgQCXRSbOoy9BjH+ViXwB3YQeix3o3YAMARkI6gopM3x/c7
m4iGxy+3d+H+Wc0VYZRYxrp1EHjgu+AKtKvvoVWgSU3CzSG1ihEPVuolhmw9KXSK
3rwyCKcfXnKUz7wNksGwlDYASn8ujxSF6XgS+JAYe8E/aBuz/2+inbLqMsN/ZJ9A
DPCaj2v3ARE5r4s5VXvfvpPL1bwiMkMLJTWZ6+dPEYbSzXH6YqS16DNTyb4UAUdi
hWT6P0xNAT2/6RxlTCkWFAWEBXyvDPIP5v+pLvBLiby7HYnuDIXF8Ma1GhiPiF0V
WsEb1ltWOBQQYVq/Fh7yGxKXXn42kxzY67I5SHgZRcJnCfxs+BtSlSiyjU+0+Cnv
qM/IspVrDGTlNBHp7tYPaMNZK5rDm5zeQpqn/PVgMttrW6QXk9CYE7w1wWnGjOL3
/VJ2VeJqxigpLXqRyDzNetxz8Z+h/po6fGG0xkwF9T9ZzCuyiWjHu4mh+dsTwo4h
57E1u+MXayF92nDaSp6JY/MIGEMtU+RefXDVTzuCojyza7c+j98=
=FUMG
-----END PGP SIGNATURE-----