USN-8814-1: Octavia vulnerabilities
It was discovered that Octavia did not properly validate TLS cipher
string fields in the Amphora provider driver. An authenticated
attacker who owns a TLS-enabled load balancer could possibly use
this issue to inject arbitrary HAProxy configuration directives.
(CVE-2026-94572)
It was discovered that Octavia did not properly validate L7 policy
redirect URL fields in the Amphora provider driver. An authenticated
attacker who owns a load balancer could possibly use this issue to
inject arbitrary HAProxy configuration directives. (CVE-2026-94571)
It was discovered that Octavia incorrectly handled quality of service
policy authorization. An authenticated attacker could possibly use
this issue to prevent deletion of another project's QoS policy.
(CVE-2026-74248)