External risk intelligence

OpenStack Octavia HAProxy Injection Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-94571

The vulnerability exists in OpenStack Octavia, a load balancing service designed to manage traffic for cloud applications. While it requires authenticated access to the load balancer management API to exploit, such services are commonly deployed in internet-facing cloud environments to manage public-facing traffic, making the management interface a targetable surface in those deployments.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in the OpenStack Octavia service, specifically within its Amphora provider driver. This issue allows an authenticated user with load balancer ownership to inject arbitrary commands into the HAProxy configuration, potentially leading to significant impacts on affected deployments. The primary concern is confirming whether your environment utilizes the Amphora provider, as other configurations are not susceptible to this flaw.

  • Allows injecting commands via load balancer settings.
  • Remember that authenticated users can compromise configurations.
  • Confirm if your environment uses the Amphora load balancer provider.

Attack Path

How an attacker could exploit the issue

An attacker with project member access to a load balancer can exploit a flaw in how OpenStack Octavia handles URLs. By submitting specially crafted redirect URLs, an attacker can inject malicious commands into the HAProxy configuration, potentially leading to a complete compromise of the affected system. This vulnerability is specific to deployments using the Amphora provider.

  • Authenticated access to load balancer management is required.
  • Control characters in redirect URLs trigger the vulnerability.
  • Risk includes arbitrary HAProxy directive injection.

Live Threat

Current exploitation, exposure, and threat context

In OpenStack Octavia deployments using the Amphora provider, an authenticated project member could inject malicious HAProxy directives. This is possible when control characters, specifically newlines, are included in L7 policy redirect fields, as Octavia does not properly sanitize these values before generating HAProxy configurations.

  • Arbitrary HAProxy directives could be injected.
  • Control characters in redirect fields allow injection.
  • May lead to unauthorized service behavior.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-World Ownership

For OpenStack Octavia deployments using the Amphora provider, load balancer owners and platform/infrastructure teams are primarily responsible for addressing this vulnerability. The first critical step is to identify all instances of the Amphora provider, confirm their network exposure, and assess their business criticality to prioritize remediation efforts.

  • Load balancer owners should initiate review.
  • Verify Amphora provider usage and exposure.
  • Plan risk-based remediation and vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is OpenStack Octavia?

OpenStack Octavia is a load-balancing service used in cloud environments to manage and distribute network traffic across application instances. It relies on provider drivers, like the Amphora driver, to configure the underlying infrastructure. In this context, Octavia automates the creation and management of load-balancing resources, acting as a critical component for ensuring high availability and performance in cloud-based architectures.

How does CVE-2026-94571 enable HAProxy directive injection?

This vulnerability involves Improper Control of Generation of Code, classified as CWE-94. The software fails to sanitize control characters, specifically newlines, within L7 policy redirect fields. Because these characters are not stripped, they are written directly into the HAProxy configuration file. This flaw allows an attacker to break out of the intended URL syntax and inject unauthorized configuration directives that the load balancer will then execute.

Does any input trigger this vulnerability?

No. The vulnerability is not triggered by standard, well-formed input. It specifically requires the inclusion of raw control characters—such as newlines—within the redirect_url or redirect_prefix fields. Furthermore, the vulnerability only exists in deployments utilizing the Amphora provider driver; alternative Octavia providers do not share this specific configuration generation flaw.

Is my environment at risk from this CVE?

You should consider the risk if you use the Amphora provider in your OpenStack Octavia deployment. According to Halo Surface Signal, because this service is often internet-facing to manage public traffic, the management interface can be a targetable surface. Since an authenticated project member is required to initiate the attack, the threat is most relevant in multi-tenant environments where project-level access is granted to untrusted or compromised users.

How should I respond to CVE-2026-94571?

Start by verifying if your infrastructure uses the Amphora provider, as other configurations are unaffected. If it is in use, review your current load balancer settings for any anomalous L7 policy configurations. Coordinate with your infrastructure and platform teams to prioritize updates for all affected Amphora instances, focusing first on those that are internet-facing or support business-critical services.

References