VYPR
High severity7.5NVD Advisory· Published Jan 29, 2016· Updated May 6, 2026

CVE-2016-0738

CVE-2016-0738

Description

OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
swiftPyPI
< 2.3.12.3.1
swiftPyPI
>= 2.4.0, < 2.5.12.5.1

Affected products

3
  • OpenStack/Swift3 versions
    cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:*range: <=2.3.0
    • cpe:2.3:a:openstack:swift:2.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:openstack:swift:2.5.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

24

News mentions

0

No linked articles in our index yet.