Medium severity6.0NVD Advisory· Published Jun 17, 2026· Updated Jun 17, 2026
CVE-2026-55748
CVE-2026-55748
Description
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
horizonPyPI | <= 25.7.3 | — |
Affected products
5- osv-coords4 versionspkg:apk/chainguard/openstack-horizon-2025.1pkg:apk/chainguard/openstack-horizon-2025.1-fipspkg:apk/chainguard/openstack-horizon-2025.2pkg:apk/chainguard/openstack-horizon-2025.2-fips
< 0+ 3 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-6wrm-x65g-hr4pghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-55748ghsaADVISORY
- launchpad.net/bugs/2152240nvdWEB
- wiki.openstack.org/wiki/OSSN/OSSN-0097nvdWEB
News mentions
0No linked articles in our index yet.