Add OSSA-2026-037 security advisory for Keystone - #1075
Merged
Conversation
✅
|
| Descriptor | Linter | Files | Fixed | Errors | Max errors | Warnings | Elapsed time |
|---|---|---|---|---|---|---|---|
| ✅ ACTION | actionlint | 5 | 0 | 0 | 0.07s | ||
| ✅ JSON | jsonlint | 4 | 0 | 0 | 0.09s | ||
| ✅ JSON | prettier | 4 | 0 | 0 | 0.33s | ||
| ✅ JSON | v8r | 4 | 0 | 0 | 9.98s | ||
| ✅ MARKDOWN | markdownlint | 169 | 0 | 0 | 2.3s | ||
| ✅ MARKDOWN | markdown-table-formatter | 169 | 0 | 0 | 0.35s | ||
| ✅ REPOSITORY | betterleaks | yes | no | no | 0.61s | ||
| ✅ REPOSITORY | checkov | yes | no | no | 18.14s | ||
| ✅ REPOSITORY | git_diff | yes | no | no | 0.07s | ||
| ✅ REPOSITORY | secretlint | yes | no | no | 3.17s | ||
| ✅ REPOSITORY | trufflehog | yes | no | no | 3.98s | ||
| ✅ SPELL | codespell | 179 | 0 | 0 | 0.65s | ||
| lychee | 179 | 21 | 0 | 38.64s | |||
| ✅ YAML | prettier | 6 | 0 | 0 | 0.35s | ||
| ✅ YAML | v8r | 6 | 0 | 0 | 6.55s | ||
| ✅ YAML | yamllint | 6 | 0 | 0 | 0.51s |
Detailed Issues
⚠️ SPELL / lychee - 21 errors
📝 Summary
---------------------
🔍 Total.........1068
🔗 Unique.........818
✅ Successful.....970
⏳ Timeouts.........6
🔀 Redirected.......5
👻 Excluded........71
❓ Unknown..........0
🚫 Errors..........21
⛔ Unsupported.....21
Errors in docs/concepts/cluster-network.md
[TIMEOUT] https://stordis.com/basic-configuration-and-management-of-sonic-devices/ (at 196:3) | Request timed out
[TIMEOUT] https://stordis.com/bgp-unnumbered-in-enterprise-sonic/ (at 66:1) | Request timed out
[TIMEOUT] https://stordis.com/deploying-bgp-underlay-in-enterprise-sonic/ (at 197:3) | Request timed out
Errors in docs/guides/deploy-guide/metalbox.md
[503] https://nbg1.your-objectstorage.com/osism/metalbox/octavia-export-2025.1.img (at 137:4) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/metalbox/octavia-export-2025.1.img (at 430:4) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/metalbox/registry-2025.1-full.tar.bz2 (at 132:4) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/metalbox/registry-2025.1-full.tar.bz2 (at 415:4) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/metalbox/registry-stable-full.tar.bz2 (at 134:4) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/metalbox/registry-stable-full.tar.bz2 (at 417:4) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/metalbox/ubuntu-noble.tar.bz2 (at 129:4) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/metalbox/ubuntu-noble.tar.bz2 (at 407:4) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-esp.raw (at 115:6) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-ipa.initramfs (at 111:6) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-ipa.kernel (at 112:6) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-metalbox-image.zip (at 96:4) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-node.qcow2 (at 113:6) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-node.qcow2.CHECKSUM (at 114:6) | Rejected status code: 503 Service Unavailable
Errors in docs/guides/deploy-guide/services/openstack.md
[TIMEOUT] https://www.openstack.org/software/project-navigator/openstack-components#openstack-services (at 14:5) | Request timed out
Errors in docs/guides/upgrade-guide/metalbox/data-updates.md
[503] https://nbg1.your-objectstorage.com/osism/metalbox/registry-stable-full.tar.bz2 (at 90:4) | Error (cached)
[503] https://nbg1.your-objectstorage.com/osism/metalbox/ubuntu-noble.tar.bz2 (at 151:4) | Error (cached)
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-esp.raw (at 57:6) | Error (cached)
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-ipa.initramfs (at 53:6) | Error (cached)
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-ipa.kernel (at 54:6) | Error (cached)
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-node.qcow2 (at 55:6) | Error (cached)
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-node.qcow2.CHECKSUM (at 56:6) | Error (cached)
Errors in docs/release-notes/osism-7.md
[TIMEOUT] https://www.openstack.org/software/openstack-bobcat (at 978:38) | Request timed out
Errors in docs/release-notes/osism-8.md
[TIMEOUT] https://www.openstack.org/software/openstack-caracal (at 223:38) | Request timed out
Hint: Followed 5 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
See detailed reports in MegaLinter artifacts
Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)
- Documentation: Custom Flavors
- Command:
npx mega-linter-runner@10.0.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,JSON_JSONLINT,JSON_V8R,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_SECRETLINT,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,SPELL_CODESPELL,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

Show us your support by starring ⭐ the repository
Document the inconsistent scope enforcement for delegated tokens in Keystone (Launchpad bugs #2153453 and #2158538, CVE ids pending). Tokens derived from EC2 credentials and OAuth1 access tokens could create trusts, application credentials and OAuth1 access tokens that outlive the original credential and carry roles the delegation never had, and application credential and EC2 tokens could be rescoped to other projects through the token authentication method. Every deployment is affected. No fixed Keystone release exists upstream yet; OSISM ships the proposed upstream patches for 2025.1, 2025.2 and 2026.1 via container-images-kolla PR #776, which also carries the ec2credential token ban from master. Community-curated backports for 2024.1 and 2024.2 are in preparation. Overriding keystone_tag is sufficient. Assisted-by: Claude:claude-fable-5 Signed-off-by: Christian Berendt <berendt@osism.tech>
osfrickler
approved these changes
Aug 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Documents the inconsistent scope enforcement for delegated tokens in Keystone
(OSSA-2026-037,
LP #2153453,
LP #2158538; two CVE ids requested from MITRE, still pending).
Tokens derived from EC2 credentials and OAuth1 access tokens could create trusts, application
credentials and OAuth1 access tokens that outlive the original credential — and, because trust
creation validates roles against the trustor's full assignments, carry roles the delegation never
had. Application credential tokens presented without a scope were rescoped to the owner's default
project, and EC2-derived tokens could be rescoped to any project of the user via the token
authentication method.
Every OSISM deployment is affected: application credentials, EC2 credentials, trusts and the token
method are available by default and
allow_rescope_scoped_tokendefaults toTrue. Exploitationrequires possession of a delegated credential.
No fixed Keystone release exists upstream yet; all eight reviews
(1002301–1002308) are
still open. OSISM ships the proposed patches for 2025.1 and 2025.2 via
container-images-kolla PR #776; the
2026.1 patches are included but those images are not published yet. Community-curated backports
for 2024.1 and 2024.2 are in preparation; the page says so and announces an update.
The remediation overrides
keystone_tagtogether withkeystone_image,keystone_fernet_imageand
keystone_ssh_image, because a stable OSISM release pulls from thekolla/release/<openstack_version>namespace while the rolling images live inkolla(see osism/defaults all/002-images-kolla.yml).
Points worth a second look:
Keystone API (997369,
[auth] ban_ec2credential_tokens,default
True). Documented as a behavior change in its own section.keystone.api._shared.delegationvia/var/lib/kolla/venv/bin/python3inside thekeystonecontainer — not tested against a liveimage yet.
Follow-ups once available: CVE ids, PR/commit of the 2024.x backports, upstream fix versions
27.0.3 / 28.0.3 / 29.0.3.
Assisted-by: Claude:claude-fable-5
🤖 Generated with Claude Code