CVE-2026-49017
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
27/05/2026
Last modified:
27/05/2026
Description
In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH



