CVE-2026-44394
Description
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
keystonePyPI | >= 14.0.0, < 27.0.2 | 27.0.2 |
keystonePyPI | >= 28.0.0, < 28.0.2 | 28.0.2 |
keystonePyPI | >= 29.0.0, < 29.0.2 | 29.0.2 |
Affected products
9- osv-coords6 versionspkg:apk/chainguard/openstack-keystone-2025.1pkg:apk/chainguard/openstack-keystone-2025.2pkg:apk/chainguard/openstack-keystone-2025.2-fipspkg:apk/chainguard/openstack-keystone-2026.1-fipspkg:apk/chainguard/openstack-keystone-2025.1-fipspkg:apk/chainguard/openstack-keystone-2026.1
< 27.0.1_git20260618-r6+ 5 more
- (no CPE)range: < 27.0.1_git20260618-r6
- (no CPE)range: < 28.0.1_git20260618-r5
- (no CPE)range: < 28.0.1_git20260618-r5
- (no CPE)range: < 29.0.1_git20260617-r6
- (no CPE)range: < 27.0.1_git20260618-r7
- (no CPE)range: < 29.0.1_git20260616-r6
Patches
Vulnerability mechanics
References
5- security.openstack.org/ossa/OSSA-2026-015.htmlnvdPatchVendor AdvisoryWEB
- bugs.launchpad.net/keystone/+bug/2150379nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-whqr-fgm5-x77qghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-44394ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/keystone/PYSEC-2026-603.yamlghsaWEB
News mentions
1- OpenStack: Six Medium-to-High CVEs Disclosed Across Neutron, Keystone, and SwiftVypr Intelligence · May 28, 2026