85 Total advisories
85 Vulnerabilities
0 Malware

Dependency scanning

Check whether keystone is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 7.2
PyPI

CVE-2017-2673

CVE-2017-2673

HIGH 7.5
PyPI

CVE-2025-65073

OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.

HIGH 7.5
PyPI

CVE-2025-65073

OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.

UNKNOWN
PyPI

CVE-2012-4457

OpenStack Keystone Token authorization for a user in a disabled tenant is allowed

UNKNOWN
PyPI

CVE-2013-4477

OpenStack Identity Keystone Privilege Escalation vulnerability

HIGH 7.5
PyPI

CVE-2021-38155

OpenStack Keystone allows information disclosure during account locking

UNKNOWN
PyPI

CVE-2012-4456

OpenStack Keystone Improper Authentication vulnerability

UNKNOWN
PyPI

CVE-2012-4457

OpenStack Keystone Token authorization for a user in a disabled tenant is allowed

HIGH 7.5
PyPI

CVE-2021-38155

OpenStack Keystone allows information disclosure during account locking

UNKNOWN
PyPI

CVE-2012-4413

OpenStack Keystone does not invalidate existing tokens when granting or revoking roles

UNKNOWN
PyPI

CVE-2012-4456

OpenStack Keystone Improper Authentication vulnerability

UNKNOWN
PyPI

CVE-2013-4477

OpenStack Identity Keystone Privilege Escalation vulnerability

MEDIUM 6.5
PyPI

CVE-2013-0270

OpenStack Keystone Denial of Service vulnerability via a large HTTP request

UNKNOWN
PyPI

CVE-2013-2014

OpenStack Identity (Keystone) Denial of Service

UNKNOWN
PyPI

CVE-2014-0204

OpenStack Identity Keystone Improper Privilege Management

UNKNOWN
PyPI

CVE-2015-3646

OpenStack Keystone Logs Passwords

UNKNOWN
PyPI

CVE-2013-0282

OpenStack Keystone allows context-dependent attackers to bypass access restrictions

UNKNOWN
PyPI

CVE-2014-3476

OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege

UNKNOWN
PyPI

CVE-2014-3621

OpenStack Identity Keystone Exposure of Sensitive Information

UNKNOWN
PyPI

CVE-2015-3646

OpenStack Keystone Logs Passwords

UNKNOWN
PyPI

CVE-2014-0204

OpenStack Identity Keystone Improper Privilege Management

UNKNOWN
PyPI

CVE-2014-3621

OpenStack Identity Keystone Exposure of Sensitive Information

MEDIUM 6.5
PyPI

CVE-2013-0270

OpenStack Keystone Denial of Service vulnerability via a large HTTP request

UNKNOWN
PyPI

CVE-2014-3476

OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege

UNKNOWN
PyPI

CVE-2013-0282

OpenStack Keystone allows context-dependent attackers to bypass access restrictions

UNKNOWN
PyPI

CVE-2013-2014

OpenStack Identity (Keystone) Denial of Service

MEDIUM 6.0
PyPI

CVE-2026-42999

OpenStack Keystone has an Authorization Bypass

MEDIUM 6.0
PyPI

CVE-2026-42998

OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential

MEDIUM 6.0
PyPI

CVE-2026-44394

OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token

MEDIUM 6.0
PyPI

CVE-2026-43000

OpenStack Keystone has an Incorrect Authorization issue

HIGH 8.8
PyPI

CVE-2026-42999

CVE-2026-42999

HIGH 8.1
PyPI

CVE-2026-44394

CVE-2026-44394

HIGH 8.8
PyPI

CVE-2026-43000

CVE-2026-43000

HIGH 8.8
PyPI

CVE-2026-42998

CVE-2026-42998

HIGH 8.0
PyPI

CVE-2026-43001

CVE-2026-43001

HIGH 7.9
PyPI

CVE-2026-43001

OpenStack Keystone has an Incorrect Authorization Issue

CRITICAL 9.1
PyPI

CVE-2021-3563

Openstack Keystone Incorrect Authorization vulnerability

UNKNOWN
PyPI

CVE-2013-1865

CVE-2013-1865

CRITICAL 9.1
PyPI

CVE-2021-3563

Openstack Keystone Incorrect Authorization vulnerability

MEDIUM 5.4
PyPI

CVE-2012-5571

OpenStack Keystone intended authorization restrictions bypass

UNKNOWN
PyPI

CVE-2019-19687

CVE-2019-19687

UNKNOWN
PyPI

CVE-2012-3542

CVE-2012-3542

UNKNOWN
PyPI

CVE-2013-2006

CVE-2013-2006

UNKNOWN
PyPI

CVE-2020-12691

CVE-2020-12691

UNKNOWN
PyPI

CVE-2020-12689

CVE-2020-12689

UNKNOWN
PyPI

CVE-2012-3426

CVE-2012-3426

UNKNOWN
PyPI

CVE-2012-5563

CVE-2012-5563

MEDIUM 5.3
PyPI

CVE-2026-33551

CVE-2026-33551

UNKNOWN
PyPI

CVE-2020-12692

CVE-2020-12692

UNKNOWN
PyPI

CVE-2012-5571

CVE-2012-5571

LOW 3.5
PyPI

CVE-2026-33551

OpenStack Keystone: Restricted application credentials can create EC2 credentials

HIGH 7.7
PyPI

CVE-2026-40683

OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean

HIGH 7.5
PyPI

CVE-2012-3542

OpenStack Keystone Allows Remote User Account Creation

UNKNOWN
PyPI

CVE-2012-4413

OpenStack Keystone does not invalidate existing tokens when granting or revoking roles

HIGH 7.5
PyPI

CVE-2014-2828

OpenStack Identity (Keystone) DoS through V3 API authentication chaining

MEDIUM 6.5
PyPI

CVE-2014-2237

OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend

MEDIUM 5.3
PyPI

CVE-2013-4294

OpenStack Identity (Keystone) allows remote attackers to bypass intended access restrictions via revoked PKI token

MEDIUM 5.3
PyPI

CVE-2013-1865

OpenStack Keystone Improper Authentication vulnerability

MEDIUM 6.5
PyPI

CVE-2014-5252

OpenStack Identity (Keystone) UUID v2 tokens does not expire with revocation events

MEDIUM 6.5
PyPI

CVE-2014-5251

OpenStack Identity (Keystone) Multiple vulnerabilities in revocation events

MEDIUM 6.5
PyPI

CVE-2014-5253

OpenStack Keystone Domain-scoped tokens don't get revoked

MEDIUM 4.3
PyPI

CVE-2016-4911

OpenStack Identity Keystone Improper Access Control

MEDIUM 4.3
PyPI

CVE-2013-2059

OpenStack Identity (Keystone) improper revoking of the authentication token when deleting a user

HIGH 7.2
PyPI

CVE-2017-2673

OpenStack Identity service (keystone) Incorrect Authorization

MEDIUM 4.3
PyPI

CVE-2016-4911

CVE-2016-4911

UNKNOWN
PyPI

CVE-2014-5251

CVE-2014-5251

UNKNOWN
PyPI

CVE-2014-2828

CVE-2014-2828

UNKNOWN
PyPI

CVE-2014-5252

CVE-2014-5252

UNKNOWN
PyPI

CVE-2013-2059

CVE-2013-2059

UNKNOWN
PyPI

CVE-2013-4294

CVE-2013-4294

UNKNOWN
PyPI

CVE-2014-5253

CVE-2014-5253

UNKNOWN
PyPI

CVE-2014-2237

CVE-2014-2237

UNKNOWN
PyPI

CVE-2012-3426

OpenStack Keystone token expiration issues

UNKNOWN
PyPI

CVE-2013-2006

OpenStack Keystone Sensitive information disclosure via log files

HIGH 8.8
PyPI

CVE-2020-12689

OpenStack Keystone EC2 and/or credential endpoints are not protected from a scoped context

MEDIUM 5.4
PyPI

CVE-2020-12692

OpenStack Keystone does not check signature TTL of the EC2 credential auth method

HIGH 7.5
PyPI

CVE-2015-7546

OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected Credentials

HIGH 8.8
PyPI

CVE-2019-19687

OpenStack Keystone Credential Leakage

HIGH 8.8
PyPI

CVE-2020-12690

Insufficient Session Expiration in OpenStack Keystone

MEDIUM 5.9
PyPI

CVE-2012-5563

OpenStack Keystone Insufficient token expiration

HIGH 8.8
PyPI

CVE-2020-12691

OpenStack Keystone V3 /credentials endpoint policy logic allows to change credentials owner or target project ID

MEDIUM 5.9
PyPI

CVE-2013-2255

OpenStack Keystone and other components vulnerable to Improper Certificate Validation

UNKNOWN
PyPI

CVE-2020-12690

CVE-2020-12690

UNKNOWN
PyPI

CVE-2018-20170

CVE-2018-20170

UNKNOWN
PyPI

PYSEC-2019-99

PYSEC-2019-99

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes