Red Hat OpenStack Platform
Red Hat® OpenStack® Platform is a cloud computing platform that virtualizes resources from industry-standard hardware, organizes those resources into clouds, and manages them so users can access what they need—when they need it.
Browse the latest documentation
View documentation for Red Hat OpenStack Services on OpenShift.Product Rebranding after 17.1
Release notesRelease information
Deploying Red Hat OpenStack Platform at scalePlanning a Red Hat OpenStack Platform deployment
Installing and managing Red Hat OpenStack Platform with directorInstalling and upgrading Red Hat OpenStack Platform
Customizing your Red Hat OpenStack Platform deploymentCustomizing your Red Hat OpenStack Platform environment
Configuring network functions virtualizationNetwork Functions Virtualization
Configuring spine-leaf networkingData center networking
Configuring Red Hat OpenStack Platform networkingVirtual networking
Latest security advisories
| Severity | Advisory/CVE | Synopsis | Date |
|---|---|---|---|
| Severity Important | Advisory/CVECVE-2026-2035366 | Synopsis A flaw was found in OpenStack Keystone where an application credential token can escape its intended project scope through token-method reauthentication. Keystone rejects an explicit scope change for an application credential token, but an omitted scope falls through to the owner's default project. If the owner has roles on that default project, Keystone issues a new token scoped there while still carrying the original application credential identity. Custom Keystone authentication plugins are subject to the same incomplete rescope guard. This allows a limited-scope application credential for one project to access another project within the owner's role assignments. | Date |
| Severity Important | Advisory/CVECVE-2026-2035364 | Synopsis A flaw was found in OpenStack Keystone where delegation boundary enforcement is incomplete across trust, application credential, and OAuth1 authorization endpoints. Tokens obtained via delegated authentication methods, such as OAuth1 access tokens or custom Keystone authentication plugins, can perform operations beyond their intended scope because endpoint guards only recognized specific delegation types rather than using a comprehensive allowlist. This allows creating trusts that delegate roles beyond the token's authorized scope, creating persistent application credentials, and authorizing new OAuth1 delegations. These derived credentials persist independently and survive revocation of the original credential, enabling an attacker with a compromised narrow-scope credential to escalate to the user's full privileges and maintain persistent access. | Date |
| Severity Important | Advisory/CVECVE-2026-71235 | Synopsis A flaw was found in Magistrala's Rules Engine. An authenticated low-privileged user can exploit this vulnerability by creating rules with embedded Go or Lua scripts. These scripts are executed server-side without sufficient validation, allowing for arbitrary file read and write operations, access to internal databases, and Server-Side Request Forgery (SSRF) against internal microservices. This could lead to significant data compromise and unauthorized system access. | Date |
| Severity Moderate | Advisory/CVECVE-2026-15792 | Synopsis A flaw was found in BuildKit. A malicious BuildKit client or frontend can craft a specially designed request, leading to the BuildKit daemon crashing. This vulnerability results in a denial of service (DoS), making the BuildKit service unavailable. | Date |
| Severity Important | Advisory/CVE(RHSA-2026:28047) Important: Red Hat OpenStack Platform 17.1 (etcd) security update | Synopsis Important: Red Hat OpenStack Platform 17.1 (etcd) security update | Date |
Top resources
Get support
Support cases
Get answers quickly by opening a support case with us.
Live chat
Directly access our support engineers during weekday business hours.
Call or email
Speak directly with a Red Hat Support expert by phone or through email.