CVE-2026-107363

CVE-2026-107363 published: In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the project identifier in subsequent requests to the project authenticated by the Keystone token. An authenticated user with a valid token for one project may substitute another project...

View full NVD advisory → ← Back to CVE watch