CVE-2026-55748
EUVD-2026-3772317.06.2026, 15:17
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| openstack | horizon | 8.0.0 ≤ 𝑥 < 25.3.3 | CNA |
| openstack | horizon | 25.4.0 ≤ 𝑥 < 25.5.3 | CNA |
| openstack | horizon | 25.6.0 ≤ 𝑥 < 25.7.4 | CNA |
Debian Releases