OSSA-2026-043: Zaqar WebSocket project substitution allows cross-project queue access

Date:

October 07, 2026

CVE:

CVE-2026-107363

Affects

  • Zaqar: >=1.0.0 <20.1.3, >=21.0.0 <21.0.3, >=22.0.0 <22.0.3, ==23.0.0

Description

Chen YuXiang from the Institute of Computing Technology, Chinese Academy of Sciences reported a vulnerability in Zaqar’s WebSocket transport. An authenticated remote attacker who knows a target project’s UUID may substitute it in subsequent WebSocket frames to enumerate, inspect, create, or delete queues belonging to that project. This may result in unauthorized disclosure, modification, or loss of queue data. Only deployments using the WebSocket transport with Keystone authentication are affected.

Errata

CVE-2026-107363 has been assigned for this vulnerability.

Patches

Credits

  • Chen YuXiang from Institute of Computing Technology, Chinese Academy of Sciences (CVE-2026-107363)

References

OSSA History

  • 2026-10-07 - Errata 1

  • 2026-10-07 - Original Version