OSSN-0109: metric association bypass across projects in Gnocchi
Advisory OSSN-0109, published on October 7, 2026 in the oss-sec feed by maintainer Goutham Pacha Ravi: authenticated users can associate metrics with other users' resources by supplying resource_id to the Gnocchi metric creation endpoint.
OSSN-0109 describes an authorization flaw in Gnocchi, a time-series metrics service. According to the advisory, the metric creation endpoint accepts a resource_id in the request body. With it, a user who is already authenticated can associate metrics with resources owned by other people, bypassing the proper authorization checks. The text received was machine-translated from the oss-sec feed and is truncated where it describes details. This summary therefore does not invent affected versions, fix dates or mitigations that do not appear in the available content.
The practical risk concerns data integrity: a malicious user, or a compromised account, could pollute metrics of another project or link information to resources they do not own. Those who operate Gnocchi should treat the advisory as a security alert and consult the original text to confirm the affected versions and the maintainer's guidance.
To verify, open the original referenced in the advisory on the public oss-sec archive and compare the mentioned versions with those your organization runs. Rota Nacional is not cited as part of this problem.