A notice published on September 24, 2026 describes CVE-2026-97404: an empty URL-Signature header in OpenStack Zaqar can bypass authentication. The available text is incomplete.
Notice OSSA-2026-042, dated September 24, 2026, reports that an empty URL-Signature header in OpenStack Zaqar can bypass authentication. It identifies the flaw as CVE-2026-97404 and lists affected versions using the notation “>=1.0.0,” “=21.0.0,” and “=22.0.0.” Since the supplied excerpt is incomplete, further details, such as fixes or mitigation steps, cannot be confirmed.
To assess the risk, consult the original notice in the oss-sec feed and verify details in official project sources, especially affected versions and any fixes. If you use AI to summarize or analyze the material, avoid including credentials, personal data, or internal system information; check conclusions against the notice before taking action.