OSSA-2026-029: Zaqar EXTRA-SPEC header bypasses Keystone authentication

Date:

July 23, 2026

CVE:

CVE-2026-66139

Affects

  • Zaqar: >=12.0.0 <20.1.1, ==21.0.0, ==22.0.0

Description

Chen YuXiang from the Institute of Computing Technology, Chinese Academy of Sciences reported that the Zaqar messaging service bypasses Keystone authentication when an EXTRA-SPEC header is present in the request. An unauthenticated attacker who knows a project UUID can read, enumerate, create, and delete that project’s queues without a Keystone token. The EXTRA-SPEC header was intended to support an alternative authentication mechanism, but the backend validation was never implemented, resulting in a complete authentication bypass. All deployments running Zaqar 12.0.0 or later are affected.

Errata

Corrected reporter name in description. CVE-2026-66139 has been assigned for this vulnerability.

Patches

Credits

  • Chen YuXiang from Institute of Computing Technology, Chinese Academy of Sciences

References

Notes

OSSA History

  • 2026-07-24 - Errata 1

  • 2026-07-23 - Original Version