Fiche vulnérabilité
CVE-2026-46448 : faille élevée openstack nova (CVSS 8.5)
Description
In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.
En bref
- Sévérité
- Élevée (CVSS 8.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 16 juin 2026
- Dernière mise à jour
- 26 juin 2026
Produits concernés
- openstack nova