id: PYSEC-2026-2520 published: "2026-07-13T15:15:37.289488Z" modified: "2026-07-13T16:04:18.035127Z" aliases: - CVE-2026-43002 - GHSA-vxvf-xvm3-p8j5 summary: OpenStack Horizon has Incorrect Behavior Order details: An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix. affected: - package: name: horizon ecosystem: PyPI purl: pkg:pypi/horizon ranges: - type: ECOSYSTEM events: - introduced: "25.6" - fixed: 25.7.3 versions: - 25.6.0 - 25.7.0 - 25.7.1 - 25.7.2 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2026-43002 - type: WEB url: https://bugs.launchpad.net/horizon/+bug/2150331 - type: PACKAGE url: https://github.com/openstack/horizon - type: WEB url: https://security.openstack.org/ossa/OSSA-2026-009.html - type: WEB url: https://www.openwall.com/lists/oss-security/2026/05/05/7 - type: PACKAGE url: https://pypi.org/project/horizon - type: ADVISORY url: https://github.com/advisories/GHSA-vxvf-xvm3-p8j5 severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L