As per upstream announce here: https://security.openstack.org/ossa/OSSA-2026-043.html OSSA-2026-043: Zaqar WebSocket project substitution allows cross-project queue access Date: October 07, 2026 CVE: CVE-2026-pending Affects ~~~~~~~ - Zaqar: >=1.0.0 <20.1.3, >=21.0.0 <21.0.3, >=22.0.0 <22.0.3, ==23.0.0 Description ~~~~~~~~~~~ Chen YuXiang from the Institute of Computing Technology, Chinese Academy of Sciences reported a vulnerability in Zaqar's WebSocket transport. An authenticated remote attacker who knows a target project's UUID may substitute it in subsequent WebSocket frames to enumerate, inspect, create, or delete queues belonging to that project. This may result in unauthorized disclosure, modification, or loss of queue data. Only deployments using the WebSocket transport with Keystone authentication are affected. Patches ~~~~~~~ - https://review.opendev.org/1009254 (2025.1/epoxy) - https://review.opendev.org/1009253 (2025.2/flamingo) - https://review.opendev.org/1009252 (2026.1/gazpacho) - https://review.opendev.org/1009251 (2026.2/hibiscus) - https://review.opendev.org/1009250 (2027.1/indri (development)) Credits ~~~~~~~ - Chen YuXiang from Institute of Computing Technology, Chinese Academy of Sciences References ~~~~~~~~~~ - https://launchpad.net/bugs/2161402 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending Notes ~~~~~ - A CVE identifier was requested from MITRE for this vulnerability on 2026-10-06. The CVE will be added to this advisory by errata once assigned.
Hello, Bug #1150261 in zaqar reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/zaqar/-/commit/9df0c38cf30a021b865de4183032c4cd3cd9fa52 ------------------------------------------------------------------------ * CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution allows cross-project queue access. Applied upstream patch "Prohibit arbitrary project-id for websocket protocol access". (Closes: #1150261): - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1150261
Hello, Bug #1150261 in zaqar reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/zaqar/-/commit/34d0c073378166b33d4872fde8ddc5bfe0f03612 ------------------------------------------------------------------------ * CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution allows cross-project queue access. Applied upstream patch "Prohibit arbitrary project-id for websocket protocol access". (Closes: #1150261): - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1150261
Hello, Bug #1150261 in zaqar reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/zaqar/-/commit/88571e409bb4e67f10c86e17a59e64f2a2d0742d ------------------------------------------------------------------------ * CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution allows cross-project queue access. Applied upstream patch "Prohibit arbitrary project-id for websocket protocol access". (Closes: #1150261): - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1150261
Hello, Bug #1150261 in zaqar reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/zaqar/-/commit/0fd73303f81faf400c1a0acdf836c3ec4d514116 ------------------------------------------------------------------------ * CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution allows cross-project queue access. Applied upstream patch "Prohibit arbitrary project-id for websocket protocol access". (Closes: #1150261): - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1150261
Hello, Bug #1150261 in zaqar reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/zaqar/-/commit/891a271612b7dff0533d4e9c98957a754fd4dedc ------------------------------------------------------------------------ * CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution allows cross-project queue access. Applied upstream patch "Prohibit arbitrary project-id for websocket protocol access". (Closes: #1150261): - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1150261
Hello, Bug #1150261 in zaqar reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/zaqar/-/commit/2995ec847bf0ad9f8eab08faf7ec2fc287af51e2 ------------------------------------------------------------------------ * CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution allows cross-project queue access. Applied upstream patch "Prohibit arbitrary project-id for websocket protocol access". (Closes: #1150261): - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1150261
Hello, Bug #1150261 in zaqar reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/zaqar/-/commit/03bb364283e79a84b604b62e191499d313327f9e ------------------------------------------------------------------------ * CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution allows cross-project queue access. Applied upstream patch "Prohibit arbitrary project-id for websocket protocol access". (Closes: #1150261): - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1150261
Hello, Bug #1150261 in zaqar reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/zaqar/-/commit/476bd9c9b3a93055e7f94b72fad18a3105261469 ------------------------------------------------------------------------ * CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution allows cross-project queue access. Applied upstream patch "Prohibit arbitrary project-id for websocket protocol access". (Closes: #1150261): - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1150261
Hello, Bug #1150261 in zaqar reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/zaqar/-/commit/5fba4ff270e828552c0ffe8a98bf4c23baea90dd ------------------------------------------------------------------------ * CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution allows cross-project queue access. Applied upstream patch "Prohibit arbitrary project-id for websocket protocol access". (Closes: #1150261): - CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1150261
We believe that the bug you reported is fixed in the latest version of
zaqar, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1150261@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated zaqar package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 07 Oct 2026 20:42:34 +0200
Source: zaqar
Architecture: source
Version: 23.0.0-2
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1150261
Changes:
zaqar (23.0.0-2) unstable; urgency=high
.
* CVE-2026-pending / OSSA-2026-043: Zaqar WebSocket project substitution
allows cross-project queue access. Applied upstream patch "Prohibit
arbitrary project-id for websocket protocol access". (Closes: #1150261):
- CVE-2026-pending_OSSA-2026-043_Prohibit_arbitrary_project-id_fo....patch
Checksums-Sha1:
fb6ae9b3410128403536d74617ab40f80a941d2d 3149 zaqar_23.0.0-2.dsc
9556f738c26e18c8a675de951be012c96b2fee79 11964 zaqar_23.0.0-2.debian.tar.xz
9fb9d7daceba1f07dd4fbfd105b6fe9c57c6ecf2 16925 zaqar_23.0.0-2_amd64.buildinfo
Checksums-Sha256:
d9886644a438db5e96f2667d5554ac6564014e1664f7770afb9a03c1934d144d 3149 zaqar_23.0.0-2.dsc
71cdc1fb6d4c7f3784186e483e17181cd748afb016297cdae73ae07de004c3f6 11964 zaqar_23.0.0-2.debian.tar.xz
7559b89f4f71c1b04fec398dfaf03102486d69d9329fa9b55427e41c9b150055 16925 zaqar_23.0.0-2_amd64.buildinfo
Files:
2a96dee3efff507b2dea7e2a0cd42665 3149 net optional zaqar_23.0.0-2.dsc
cda2aa8e8784d59eef2296ed0dd4c38b 11964 net optional zaqar_23.0.0-2.debian.tar.xz
7a04cbed0bfa4278dcb78b733743a2ce 16925 net optional zaqar_23.0.0-2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmrGl+gACgkQ1BatFaxr
Q/5lpg//ZaJD/flUBE9abm0/G8WB6SmNHan4U8G3z4nfxMQsf7CkNbulv5RGZPx7
52u3MlVeXTASFhl/e4h9FhmQs6Dw/1Z/Dr7Nmd+WN9PJuXF2z3wTOq/edx42OWto
ysouRS3c9QKNdcMzfjgQCXRSbOoy9BjH+ViXwB3YQeix3o3YAMARkI6gopM3x/c7
m4iGxy+3d+H+Wc0VYZRYxrp1EHjgu+AKtKvvoVWgSU3CzSG1ihEPVuolhmw9KXSK
3rwyCKcfXnKUz7wNksGwlDYASn8ujxSF6XgS+JAYe8E/aBuz/2+inbLqMsN/ZJ9A
DPCaj2v3ARE5r4s5VXvfvpPL1bwiMkMLJTWZ6+dPEYbSzXH6YqS16DNTyb4UAUdi
hWT6P0xNAT2/6RxlTCkWFAWEBXyvDPIP5v+pLvBLiby7HYnuDIXF8Ma1GhiPiF0V
WsEb1ltWOBQQYVq/Fh7yGxKXXn42kxzY67I5SHgZRcJnCfxs+BtSlSiyjU+0+Cnv
qM/IspVrDGTlNBHp7tYPaMNZK5rDm5zeQpqn/PVgMttrW6QXk9CYE7w1wWnGjOL3
/VJ2VeJqxigpLXqRyDzNetxz8Z+h/po6fGG0xkwF9T9ZzCuyiWjHu4mh+dsTwo4h
57E1u+MXayF92nDaSp6JY/MIGEMtU+RefXDVTzuCojyza7c+j98=
=FUMG
-----END PGP SIGNATURE-----