Skip to content
Rota Nacional

Cyber ·

OSSA-2026-043: OpenStack Zaqar allows access to other projects' queues via WebSocket

Security advisory dated October 7, 2026 on project substitution in OpenStack's Zaqar message queue service through the WebSocket channel. The CVE is still pending and the affected-version list in the feed is incomplete.

On October 7, 2026, the OpenStack project published advisory OSSA-2026-043, describing a flaw in Zaqar, OpenStack's message queue service. According to the advisory title, project substitution over the WebSocket channel allows access to queues belonging to other projects. The CVE identifier is listed as pending, meaning it had not been assigned in the content received. The text was republished through machine translation from a public disclosure list (oss-sec), crediting the researcher who found the issue.

The available content is incomplete. The affected-versions section shows truncated and ambiguous ranges, so it is not possible to state safely which releases are vulnerable or which fixes exist. The detailed technical description was not reproduced. This material gives no indication of known exploitation.

For readers, the relevance is any OpenStack deployment running Zaqar, especially with several projects or tenants in the same environment. Rota Nacional does not fix or address this flaw, which belongs to OpenStack's own infrastructure. To check exposure, consult the original advisory on the oss-sec list or the official OpenStack security site, confirm the Zaqar version installed, and apply the fixes published by the project.

If you use AI to study or summarize this advisory, do not paste real configurations, tokens, passwords, internal project names or queue logs into prompts. Use only the public text.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free