OSSA-2026-043: Zaqar WebSocket project substitution allows cross-project queue access¶
- Date:
October 07, 2026
- CVE:
CVE-2026-107363
Affects¶
Zaqar: >=1.0.0 <20.1.3, >=21.0.0 <21.0.3, >=22.0.0 <22.0.3, ==23.0.0
Description¶
Chen YuXiang from the Institute of Computing Technology, Chinese Academy of Sciences reported a vulnerability in Zaqar’s WebSocket transport. An authenticated remote attacker who knows a target project’s UUID may substitute it in subsequent WebSocket frames to enumerate, inspect, create, or delete queues belonging to that project. This may result in unauthorized disclosure, modification, or loss of queue data. Only deployments using the WebSocket transport with Keystone authentication are affected.
Errata¶
CVE-2026-107363 has been assigned for this vulnerability.
Patches¶
https://review.opendev.org/1009254 (2025.1/epoxy)
https://review.opendev.org/1009253 (2025.2/flamingo)
https://review.opendev.org/1009252 (2026.1/gazpacho)
https://review.opendev.org/1009251 (2026.2/hibiscus)
https://review.opendev.org/1009250 (2027.1/indri (development))
Credits¶
Chen YuXiang from Institute of Computing Technology, Chinese Academy of Sciences (CVE-2026-107363)
References¶
OSSA History¶
2026-10-07 - Errata 1
2026-10-07 - Original Version