OSSA-2026-035: Unauthorized QoS policy deletion lock

Date:

August 13, 2026

CVE:

CVE-2026-74248

Affects

  • Octavia: <16.0.2, ==17.0.0, ==18.0.0

Description

Chen YuXiang with the Institute of Computing Technology, Chinese Academy of Sciences, reported a vulnerability in Octavia quality of service (QoS) policy authorization. By associating another project’s QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected.

Errata

MITRE assigned CVE-2026-74248 after intial publication.

Patches

Credits

  • Chen YuXiang from Institute of Computing Technology, Chinese Academy of Sciences (CVE-2026-74248)

References

OSSA History

  • 2026-08-17 - Errata 1

  • 2026-08-13 - Original Version