VYPR

Watcher

by OpenStack

CVEs (1)

  • CVE-2026-76878HigAug 19, 2026
    risk 0.55cvss epss

    In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false…