CVE-2025-65073
Vulnerability Summary
Timeline
Description
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
EPSS Trends
Current EPSS score: 0.23%• Percentile: 14%
Techniques & Countermeasures
- CWE-863•Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Affected Systems
- debian•keystone
< 2:18.1.0-1+deb11u2 | < 2:22.0.2-0+deb12u1 | < 2:27.0.0-3+deb13u1 | < 2:28.0.0-2
- ubuntu•heat
all | all | all | all | all | all | all
- ubuntu•keystone
all | all | all | < 2:21.0.1-0ubuntu2.1 | < 2:25.0.0-0ubuntu1.1 | < 2:28.0.0-0ubuntu1.1 | < 2:28.0.0-0ubuntu2
- ubuntu•swift
all | all | all | < 2.29.2-0ubuntu1.1 | < 2.33.0-0ubuntu1.1 | < 2.36.0-0ubuntu1.1
- openstack•keystone
< 26.0.1 | 27.0.0 | 28.0.0
- PyPI•keystone
< 26.0.1 | ≥ 27.0.0.0rc1, < 27.0.0 | ≥ 28.0.0.0rc1, < 28.0.0
- redhat•openstack-keystone
< 1:23.0.3-18.0.20241202141842.9e3dfb4.el9ost
- redhat•python3-keystone
< 1:23.0.3-18.0.20241202141842.9e3dfb4.el9ost
References (17)
- https://www.openwall.com/lists/oss-security/2025/11/04/2
- http://www.openwall.com/lists/oss-security/2025/11/17/6
- https://nvd.nist.gov/vuln/detail/CVE-2025-65073
- https://github.com/openstack/keystone
- https://pypi.org/project/keystone
- https://github.com/advisories/GHSA-hcqg-5g63-7j9h
- https://access.redhat.com/errata/RHSA-2026:1958
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=2415344
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_1958.json
- https://access.redhat.com/security/cve/CVE-2025-65073
- https://www.cve.org/CVERecord?id=CVE-2025-65073
- https://security.openstack.org/ossa/OSSA-2025-002.html
- https://ubuntu.com/security/CVE-2025-65073
- https://ubuntu.com/security/notices/USN-7857-1
- https://ubuntu.com/security/notices/USN-7926-1
- https://security-tracker.debian.org/tracker/CVE-2025-65073