CVE-2026-46448

Severity CVSS v4.0:
Pending analysis
Type:
CWE-669 Incorrect Resource Transfer Between Spheres
Publication date:
16/06/2026
Last modified:
26/06/2026

Description

In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* 18.0.0 (including) 31.3.1 (excluding)
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* 32.0.0 (including) 32.2.1 (excluding)
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* 33.0.0 (including) 33.0.2 (excluding)