Skip to content
Rota Nacional

Cyber ·

Errata 1 of OSSA-2026-043: flaw in OpenStack Zaqar allows queue access across projects

Errata 1 of advisory OSSA-2026-043 assigns CVE-2026-107363 to a flaw in the Zaqar WebSocket, the OpenStack queue service, that allows access to queues of other projects through project substitution. The advisory lists versions from 1.0.0 as affected.

According to the errata published on 7 October 2026 in the oss-sec feed, CVE-2026-107363 was assigned to the vulnerability described in advisory OSSA-2026-043. The flaw is in the WebSocket of Zaqar, the OpenStack queue service, and allows a request to access queues belonging to another project through project substitution. The affected field lists Zaqar from version 1.0.0. The received text is an automatic translation and was cut before any fix section, so this piece cannot state which version corrects the problem or which mitigations the vendor recommends.

To confirm these details, consult the original advisory in the oss-sec feed, identified by number OSSA-2026-043 and errata 1, and compare it with the official OpenStack project page. Check the Zaqar version in use, the list of fixes, and the guidance on isolation between projects before taking any action.

The relevance for teams running queues in private clouds is isolation between projects. A flaw of this kind can expose messages belonging to other teams or customers. Rota Nacional does not fix or replace Zaqar: the platform serves AI model calls, transcription, document extraction and, in preview, embeddings, voice, image and OCR jobs. If anyone uses AI to study this advisory, do not paste real project names, tokens, internal endpoints or queue messages. Replace such data with generic placeholders before sending the text.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free