GHSA-8xwf-cr4r-856r · Severity: critical · Ecosystem: pip — OpenStack Vitrage: Unauthorized Access to the Host can Lead to Eval Injection
In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This may result in unauthorized access to the host and further compromise of the Vitrage service. All deployments exposing the Vitrage API are affected. This occurs in _create_query_function in vitrage/graph/query.py.
Conclusion & alert: CVE-2026-28370 is rated Exploit Available (53.8/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.03%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-21 | 0.08% | 0.03% | -0.06% |
| 2 | 2026-02-27 | — | 0.08% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.1 | 3.1 | CRITICAL |
|
2.3 | 6.0 | [email protected] |
GHSA-8xwf-cr4r-856r · Severity: critical · Ecosystem: pip — OpenStack Vitrage: Unauthorized Access to the Host can Lead to Eval Injection
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2026-28370 not yet assigned priority: Debian including 1 source packages (vitrage), 3 status rows across 3 suites (bookworm, bullseye, trixie): open 3. | https://security-tracker.debian.org/tracker/CVE-2026-28370 |
ubuntu
|
medium | CVE-2026-28370 medium priority: Ubuntu including 1 source packages (vitrage), 5 status rows across 5 suites (focal, jammy, noble, questing, upstream): needs-triage 5. | https://ubuntu.com/security/CVE-2026-28370 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| openstack | vitrage | < 12.01 | cpe:2.3:a:openstack:vitrage:*:*:*:*:*:*:*:* |
| openstack | vitrage | >= 13.0.0, < 13.0.1 | cpe:2.3:a:openstack:vitrage:*:*:*:*:*:*:*:* |
| openstack | vitrage | >= 14.0.0, < 14.0.1 | cpe:2.3:a:openstack:vitrage:*:*:*:*:*:*:*:* |
| openstack | vitrage | >= 15.0.0, < 15.0.1 | cpe:2.3:a:openstack:vitrage:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/openstack/vitrage/blob/a1f86950e1314b0c740f9cd9b7e9dbab7d02af51/vitrage/graph/query.py#L70 | Issue Tracking |
| https://storyboard.openstack.org/#%21/story/2011539 | Exploit Issue Tracking Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/03/03/6 |