CVE-2013-0270

OpenStack Keystone Denial of Service vulnerability via a large HTTP request

mediumEPSS 3.2%

Description

A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources on the affected system.

Metrics

Severity
medium
no public PoC known
6.5
Source: nvd-v3
87.2 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
3.2 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-07-02 14:13 UTC
CWE-1284

Weakness classes (CWE)

  • CWE-1284Base

    Improper Validation of Specified Quantity in Input

    The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-07-30 14:16 UTC· secalert@redhat.com
    • Reference: https://access.redhat.com/errata/RHSA-2013:0708
    • Affected: Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2 (+4)OpenStack Folsom for RHEL 6, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2 (+5)

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • openstack

    keystone2012.1 – 2012.1.3

  • openstack

    keystone2012.2 – 2012.2.4

  • openstack

    keystone

References & sources

IDCVE-2013-0270