Dependency scanning
Check whether keystone is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2017-2673
CVE-2017-2673
CVE-2025-65073
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
CVE-2025-65073
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
CVE-2012-4457
OpenStack Keystone Token authorization for a user in a disabled tenant is allowed
CVE-2013-4477
OpenStack Identity Keystone Privilege Escalation vulnerability
CVE-2021-38155
OpenStack Keystone allows information disclosure during account locking
CVE-2012-4456
OpenStack Keystone Improper Authentication vulnerability
CVE-2012-4457
OpenStack Keystone Token authorization for a user in a disabled tenant is allowed
CVE-2021-38155
OpenStack Keystone allows information disclosure during account locking
CVE-2012-4413
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles
CVE-2012-4456
OpenStack Keystone Improper Authentication vulnerability
CVE-2013-4477
OpenStack Identity Keystone Privilege Escalation vulnerability
CVE-2013-0270
OpenStack Keystone Denial of Service vulnerability via a large HTTP request
CVE-2013-2014
OpenStack Identity (Keystone) Denial of Service
CVE-2014-0204
OpenStack Identity Keystone Improper Privilege Management
CVE-2015-3646
OpenStack Keystone Logs Passwords
CVE-2013-0282
OpenStack Keystone allows context-dependent attackers to bypass access restrictions
CVE-2014-3476
OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege
CVE-2014-3621
OpenStack Identity Keystone Exposure of Sensitive Information
CVE-2015-3646
OpenStack Keystone Logs Passwords
CVE-2014-0204
OpenStack Identity Keystone Improper Privilege Management
CVE-2014-3621
OpenStack Identity Keystone Exposure of Sensitive Information
CVE-2013-0270
OpenStack Keystone Denial of Service vulnerability via a large HTTP request
CVE-2014-3476
OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege
CVE-2013-0282
OpenStack Keystone allows context-dependent attackers to bypass access restrictions
CVE-2013-2014
OpenStack Identity (Keystone) Denial of Service
CVE-2026-42999
OpenStack Keystone has an Authorization Bypass
CVE-2026-42998
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
CVE-2026-44394
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
CVE-2026-43000
OpenStack Keystone has an Incorrect Authorization issue
CVE-2026-42999
CVE-2026-42999
CVE-2026-44394
CVE-2026-44394
CVE-2026-43000
CVE-2026-43000
CVE-2026-42998
CVE-2026-42998
CVE-2026-43001
CVE-2026-43001
CVE-2026-43001
OpenStack Keystone has an Incorrect Authorization Issue
CVE-2021-3563
Openstack Keystone Incorrect Authorization vulnerability
CVE-2013-1865
CVE-2013-1865
CVE-2021-3563
Openstack Keystone Incorrect Authorization vulnerability
CVE-2012-5571
OpenStack Keystone intended authorization restrictions bypass
CVE-2019-19687
CVE-2019-19687
CVE-2012-3542
CVE-2012-3542
CVE-2013-2006
CVE-2013-2006
CVE-2020-12691
CVE-2020-12691
CVE-2020-12689
CVE-2020-12689
CVE-2012-3426
CVE-2012-3426
CVE-2012-5563
CVE-2012-5563
CVE-2026-33551
CVE-2026-33551
CVE-2020-12692
CVE-2020-12692
CVE-2012-5571
CVE-2012-5571
CVE-2026-33551
OpenStack Keystone: Restricted application credentials can create EC2 credentials
CVE-2026-40683
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
CVE-2012-3542
OpenStack Keystone Allows Remote User Account Creation
CVE-2012-4413
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles
CVE-2014-2828
OpenStack Identity (Keystone) DoS through V3 API authentication chaining
CVE-2014-2237
OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend
CVE-2013-4294
OpenStack Identity (Keystone) allows remote attackers to bypass intended access restrictions via revoked PKI token
CVE-2013-1865
OpenStack Keystone Improper Authentication vulnerability
CVE-2014-5252
OpenStack Identity (Keystone) UUID v2 tokens does not expire with revocation events
CVE-2014-5251
OpenStack Identity (Keystone) Multiple vulnerabilities in revocation events
CVE-2014-5253
OpenStack Keystone Domain-scoped tokens don't get revoked
CVE-2016-4911
OpenStack Identity Keystone Improper Access Control
CVE-2013-2059
OpenStack Identity (Keystone) improper revoking of the authentication token when deleting a user
CVE-2017-2673
OpenStack Identity service (keystone) Incorrect Authorization
CVE-2016-4911
CVE-2016-4911
CVE-2014-5251
CVE-2014-5251
CVE-2014-2828
CVE-2014-2828
CVE-2014-5252
CVE-2014-5252
CVE-2013-2059
CVE-2013-2059
CVE-2013-4294
CVE-2013-4294
CVE-2014-5253
CVE-2014-5253
CVE-2014-2237
CVE-2014-2237
CVE-2012-3426
OpenStack Keystone token expiration issues
CVE-2013-2006
OpenStack Keystone Sensitive information disclosure via log files
CVE-2020-12689
OpenStack Keystone EC2 and/or credential endpoints are not protected from a scoped context
CVE-2020-12692
OpenStack Keystone does not check signature TTL of the EC2 credential auth method
CVE-2015-7546
OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected Credentials
CVE-2019-19687
OpenStack Keystone Credential Leakage
CVE-2020-12690
Insufficient Session Expiration in OpenStack Keystone
CVE-2012-5563
OpenStack Keystone Insufficient token expiration
CVE-2020-12691
OpenStack Keystone V3 /credentials endpoint policy logic allows to change credentials owner or target project ID
CVE-2013-2255
OpenStack Keystone and other components vulnerable to Improper Certificate Validation
CVE-2020-12690
CVE-2020-12690
CVE-2018-20170
CVE-2018-20170
PYSEC-2019-99
PYSEC-2019-99
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes