In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 27 May 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0. | |
| First Time appeared |
Openstack
Openstack swift |
|
| Weaknesses | CWE-835 | |
| CPEs | cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack swift |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-27T01:57:58.831Z
Reserved: 2026-05-27T01:57:58.189Z
Link: CVE-2026-49017
No data.
Status : Received
Published: 2026-05-27T02:16:34.327
Modified: 2026-05-27T02:16:34.327
Link: CVE-2026-49017
No data.
OpenCVE Enrichment
Updated: 2026-05-27T03:30:06Z
Weaknesses