CVE-2026-97149

CVE-2026-97149 published: In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, and path, and thus the list of disallowed headers is the only defense against a signed PUT r...

View full NVD advisory → ← Back to CVE watch