{"id":"CVE-2026-94572","published":"2026-09-21T21:17:22.150","lastModified":"2026-09-21T21:17:22.150","description":"In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the amphora, and thus an authenticated project member who owns a TLS-enabled load balancer can embed a newline and inject arbitrary HAProxy configuration directives. Only deployments using the Amphora provider are affected.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-94"],"vendors":[],"products":[],"references":[{"url":"https://bugs.debian.org/1148175","tags":[]},{"url":"https://bugs.launchpad.net/octavia/+bug/2162101","tags":[]},{"url":"https://bugs.launchpad.net/octavia/+bug/2167565","tags":[]},{"url":"https://opendev.org/openstack/octavia/commit/cad62902e4984a46ad80cbfa943e90006d8d599d","tags":[]},{"url":"https://openwall.com/lists/oss-security/2026/09/21/6","tags":[]},{"url":"https://security.openstack.org/ossa/OSSA-2026-039.html","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}