<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:41:13 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-327969</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-327969</link>
      <description>EUVD-2026-327969</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-327969</guid>
    </item>
    <item>
      <title>fkie_cve-2026-46448</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46448</link>
      <description>&lt;p&gt;In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-46448</guid>
    </item>
    <item>
      <title>GHSA-mfg3-p6m3-gjgr — OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mfg3-p6m3-gjgr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: nova&lt;/p&gt;
&lt;p&gt;## Affects&lt;/p&gt;
&lt;p&gt;- Nova: &amp;gt;=18.0.0 &amp;lt;31.3.1, &amp;gt;=32.0.0 &amp;lt;32.2.1, &amp;gt;=33.0.0 &amp;lt;33.0.2&lt;/p&gt;
&lt;p&gt;## Description
Erichen from the Institute of Computing Technology, Chinese Academy of 
Sciences reported that Nova&amp;#39;s server create API does not strip internal 
scheduler hints. An authenticated user can bypass Placement resource 
claims and scheduling constraint enforcement, including availability 
zone, host aggregate, and image trait restrictions. The resulting 
instance has no Placement allocation, which can lead to compute node 
resource exhaustion and cross-tenant data persistence on NVMe devices 
after instance deletion. Deployments running Nova 18.0.0 or later are 
affected.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;- https://review.opendev.org/993604 (2025.1/epoxy)
- https://review.opendev.org/993603 (2025.2/flamingo)
- https://review.opendev.org/993602 (2026.1/gazpacho)
- https://review.opendev.org/993601 (2026.2/hibiscus)&lt;/p&gt;
&lt;p&gt;## Credits
- Erichen from Institute of Computing Technology, Chinese Academy of 
Sciences (CVE-2026-46448)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: nova&lt;/p&gt;
&lt;p&gt;## Affects&lt;/p&gt;
&lt;p&gt;- Nova: &amp;gt;=18.0.0 &amp;lt;31.3.1, &amp;gt;=32.0.0 &amp;lt;32.2.1, &amp;gt;=33.0.0 &amp;lt;33.0.2&lt;/p&gt;
&lt;p&gt;## Description
Erichen from the Institute of Computing Technology, Chinese Academy of 
Sciences reported that Nova&amp;#39;s server create API does not strip internal 
scheduler hints. An authenticated user can bypass Placement resource 
claims and scheduling constraint enforcement, including availability 
zone, host aggregate, and image trait restrictions. The resulting 
instance has no Placement allocation, which can lead to compute node 
resource exhaustion and cross-tenant data persistence on NVMe devices 
after instance deletion. Deployments running Nova 18.0.0 or later are 
affected.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;- https://review.opendev.org/993604 (2025.1/epoxy)
- https://review.opendev.org/993603 (2025.2/flamingo)
- https://review.opendev.org/993602 (2026.1/gazpacho)
- https://review.opendev.org/993601 (2026.2/hibiscus)&lt;/p&gt;
&lt;p&gt;## Credits
- Erichen from Institute of Computing Technology, Chinese Academy of 
Sciences (CVE-2026-46448)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mfg3-p6m3-gjgr</guid>
    </item>
    <item>
      <title>PYSEC-2026-2686 — OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2686</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: nova&lt;/p&gt;
&lt;p&gt;## Affects&lt;/p&gt;
&lt;p&gt;- Nova: &amp;gt;=18.0.0 &amp;lt;31.3.1, &amp;gt;=32.0.0 &amp;lt;32.2.1, &amp;gt;=33.0.0 &amp;lt;33.0.2&lt;/p&gt;
&lt;p&gt;## Description
Erichen from the Institute of Computing Technology, Chinese Academy of 
Sciences reported that Nova&amp;#39;s server create API does not strip internal 
scheduler hints. An authenticated user can bypass Placement resource 
claims and scheduling constraint enforcement, including availability 
zone, host aggregate, and image trait restrictions. The resulting 
instance has no Placement allocation, which can lead to compute node 
resource exhaustion and cross-tenant data persistence on NVMe devices 
after instance deletion. Deployments running Nova 18.0.0 or later are 
affected.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;- https://review.opendev.org/993604 (2025.1/epoxy)
- https://review.opendev.org/993603 (2025.2/flamingo)
- https://review.opendev.org/993602 (2026.1/gazpacho)
- https://review.opendev.org/993601 (2026.2/hibiscus)&lt;/p&gt;
&lt;p&gt;## Credits
- Erichen from Institute of Computing Technology, Chinese Academy of 
Sciences (CVE-2026-46448)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: nova&lt;/p&gt;
&lt;p&gt;## Affects&lt;/p&gt;
&lt;p&gt;- Nova: &amp;gt;=18.0.0 &amp;lt;31.3.1, &amp;gt;=32.0.0 &amp;lt;32.2.1, &amp;gt;=33.0.0 &amp;lt;33.0.2&lt;/p&gt;
&lt;p&gt;## Description
Erichen from the Institute of Computing Technology, Chinese Academy of 
Sciences reported that Nova&amp;#39;s server create API does not strip internal 
scheduler hints. An authenticated user can bypass Placement resource 
claims and scheduling constraint enforcement, including availability 
zone, host aggregate, and image trait restrictions. The resulting 
instance has no Placement allocation, which can lead to compute node 
resource exhaustion and cross-tenant data persistence on NVMe devices 
after instance deletion. Deployments running Nova 18.0.0 or later are 
affected.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;- https://review.opendev.org/993604 (2025.1/epoxy)
- https://review.opendev.org/993603 (2025.2/flamingo)
- https://review.opendev.org/993602 (2026.1/gazpacho)
- https://review.opendev.org/993601 (2026.2/hibiscus)&lt;/p&gt;
&lt;p&gt;## Credits
- Erichen from Institute of Computing Technology, Chinese Academy of 
Sciences (CVE-2026-46448)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2686</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-46448</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46448</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: nova, Ubuntu:Pro:18.04:LTS: nova, Ubuntu:Pro:20.04:LTS: nova, Ubuntu:22.04:LTS: nova, Ubuntu:24.04:LTS: nova, Ubuntu:25.10: nova, Ubuntu:26.04:LTS: nova&lt;/p&gt;
&lt;p&gt;In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: nova, Ubuntu:Pro:18.04:LTS: nova, Ubuntu:Pro:20.04:LTS: nova, Ubuntu:22.04:LTS: nova, Ubuntu:24.04:LTS: nova, Ubuntu:25.10: nova, Ubuntu:26.04:LTS: nova&lt;/p&gt;
&lt;p&gt;In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46448</guid>
    </item>
  </channel>
</rss>
