Skip to content
VulniPulse
Advisory severityHigh7.5Vendor: MediumRed Hat Linux

High [CVE-2026-71190] Unauthenticated denial of service via catastrophic backtracking in Accept header parser

This high-severity Red Hat Linux advisory covers CVE-2026-71190.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-71190 Source published Source updated

VulniPulse record published Record updated

Related products & platforms
Red Hat LinuxUnclassified
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Unauthenticated denial of service via catastrophic backtracking in Accept header parser. Red Hat rates this moderate (CVSS 7.5).

Weakness: CWE-1333.

Affected versions
  • 2.38.0

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Fixed versions

No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Deploy a reverse proxy (such as HAProxy, nginx, or Apache httpd) in front of the Swift proxy server and configure it to limit the size of the Accept request header. A limit of 256 bytes is sufficient for all legitimate Accept header values used by Swift clients. For example, in HAProxy: use 'http-request deny if { req.hdr(accept) -m len gt 256 }'. In nginx: use 'large_client_header_buffers' to restrict header size. Alternatively, a WAF rule can be deployed to reject Accept headers containing backslash characters in quoted strings without a closing quote, though the header size limit is simpler and more robust. Note that Swift's built-in max_header_size (default 8192 bytes) does NOT mitigate this vulnerability because the exponential backtracking is triggered with as few as 27 backslash-character pairs (~54 bytes). In Red Hat OpenStack Services on OpenShift (RHOSO) environments, the Swift API is deployed behind an OpenShift-managed HAProxy load balancer. The available OCP route annotations do not support custom header inspection rules such as 'http-request deny if', making the header size limit approach not feasible. Rate limiting via route annotations (e.g., rate-limit-connections.rate-http) provides only partial protection, as a single crafted request can still lock a proxy worker for minutes, and attackers using multiple source IPs can bypass per-IP limits. Additionally, default rate limits cannot be shipped as a mitigation because they would break deployer configurations. For RHOSO deployments, applying the upstream patch backport is the only effective remediation.

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.