Dependency scanning
Check whether nova is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2024-40767
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
CVE-2024-40767
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
CVE-2013-4278
OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
CVE-2014-8333
OpenStack Nova VMware instance leak potentially leading to compute DoS
CVE-2013-4469
OpenStack Compute (Nova) Denial of service due to improper validation of virtual size of QCOW2 image
CVE-2015-8749
OpenStack Nova Potential Xen connection password leak via StorageError
CVE-2013-4463
OpenStack Nova denial of service through compressed disk images
CVE-2016-2140
OpenStack Nova host data access through resize/migration
CVE-2013-7048
OpenStack Nova live snapshots use an insecure local directory
CVE-2022-37394
OpenStack Nova Changing vnic_type breaks compute service restart
CVE-2013-6437
OpenStack Nova DoS through ephemeral disk backing files
CVE-2015-9543
OpenStack Nova can leak consoleauth token into log files
CVE-2013-4497
OpenStack Compute Nova Improper Access Control
CVE-2013-2096
OpenStack Compute (Nova) does not verify the virtual size of a QCOW2 image
CVE-2011-4596
OpenStack Nova Multiple directory traversal vulnerabilities
CVE-2014-0167
OpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests
CVE-2012-1585
OpenStack Nova Long server names grow nova-api log files significantly
CVE-2013-6419
OpenStack Nova Router metadata queries are not restricted by tenant
CVE-2013-4185
OpenStack Nova Denial of Service in network source security groups
CVE-2011-4596
OpenStack Nova Multiple directory traversal vulnerabilities
CVE-2013-4185
OpenStack Nova Denial of Service in network source security groups
CVE-2012-1585
OpenStack Nova Long server names grow nova-api log files significantly
CVE-2014-0167
OpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests
CVE-2015-3280
OpenStack Compute (nova) allows remote authenticated users to cause a denial of service
CVE-2013-4179
OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
CVE-2013-2096
OpenStack Compute (Nova) does not verify the virtual size of a QCOW2 image
CVE-2013-6437
OpenStack Nova DoS through ephemeral disk backing files
CVE-2014-8333
OpenStack Nova VMware instance leak potentially leading to compute DoS
CVE-2013-7048
OpenStack Nova live snapshots use an insecure local directory
CVE-2015-8749
OpenStack Nova Potential Xen connection password leak via StorageError
CVE-2014-3608
OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
CVE-2013-2256
OpenStack Compute (Nova) allows remote authenticated users to obtain sensitive information
CVE-2015-7713
OpenStack Compute (Nova) allows remote attackers to bypass intended restriction
CVE-2013-4463
OpenStack Nova denial of service through compressed disk images
CVE-2016-2140
OpenStack Nova host data access through resize/migration
CVE-2013-4469
OpenStack Compute (Nova) Denial of service due to improper validation of virtual size of QCOW2 image
CVE-2013-4278
OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
CVE-2013-4497
OpenStack Compute Nova Improper Access Control
CVE-2014-3708
OpenStack Compute (Nova) Denial of Service vulnerability
CVE-2015-3241
OpenStack Nova instance migration process does not stop when instance is deleted
CVE-2015-9543
OpenStack Nova can leak consoleauth token into log files
CVE-2013-6419
OpenStack Nova Router metadata queries are not restricted by tenant
CVE-2014-3517
OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2015-0259
OpenStack Compute (Nova) has Insufficient Verification of Data Authenticity
CVE-2022-37394
OpenStack Nova Changing vnic_type breaks compute service restart
CVE-2017-16239
OpenStack Nova Filter Scheduler Bypass
CVE-2017-18191
OpenStack Nova Denial of service attack on the compute host
CVE-2011-4076
OpenStack Nova Exposure of Sensitive Information to an Unauthorized Actor
CVE-2017-17051
OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
CVE-2011-3147
Openstack nova qcow format could expose host filesystem information
CVE-2021-3654
Open Redirect in CPython that affects users of OpenStack Nova
CVE-2017-16239
OpenStack Nova Filter Scheduler Bypass
CVE-2017-17051
OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
CVE-2011-3147
Openstack nova qcow format could expose host filesystem information
CVE-2011-4076
OpenStack Nova Exposure of Sensitive Information to an Unauthorized Actor
CVE-2017-18191
OpenStack Nova Denial of service attack on the compute host
CVE-2021-3654
Open Redirect in CPython that affects users of OpenStack Nova
CVE-2017-7214
OpenStack Nova logs sensitive context from notification exceptions
CVE-2017-7214
OpenStack Nova logs sensitive context from notification exceptions
CVE-2014-3608
OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
CVE-2015-7713
OpenStack Compute (Nova) allows remote attackers to bypass intended restriction
CVE-2014-3517
OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2015-3280
OpenStack Compute (nova) allows remote authenticated users to cause a denial of service
CVE-2013-4179
OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
CVE-2013-2256
OpenStack Compute (Nova) allows remote authenticated users to obtain sensitive information
CVE-2015-0259
OpenStack Compute (Nova) has Insufficient Verification of Data Authenticity
CVE-2014-3708
OpenStack Compute (Nova) Denial of Service vulnerability
CVE-2026-46448
OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints
CVE-2012-3361
CVE-2012-3361
CVE-2012-3371
CVE-2012-3371
CVE-2020-17376
CVE-2020-17376
CVE-2019-14433
CVE-2019-14433
CVE-2012-5625
CVE-2012-5625
CVE-2012-3447
CVE-2012-3447
CVE-2012-3360
CVE-2012-3360
CVE-2012-2654
CVE-2012-2654
CVE-2012-2101
CVE-2012-2101
CVE-2012-5625
OpenStack Nova Information leak in libvirt LVM-backed instances
CVE-2012-5625
CVE-2012-5625
CVE-2026-24708
OpenStack Nova calls qemu-img without format restrictions for resize
CVE-2024-32498
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
PYSEC-2013-45
PYSEC-2013-45
CVE-2022-47951
OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
CVE-2015-3241
OpenStack Nova instance migration process does not stop when instance is deleted
CVE-2014-2573
OpenStack Nova VMWare driver leaks rescued images
CVE-2014-0134
OpenStack Nova host data leak to vm instance in rescue mode
CVE-2015-2687
OpenStack Compute (Nova) Improper Access Control
CVE-2013-1838
OpenStack Compute (Nova) Denial of service via a large number of calls to the addFixedIp function
CVE-2013-7130
OpenStack Nova Live migration can leak root disk into ephemeral storage
CVE-2013-0335
OpenStack Compute Nova Unauthorised access to arbitrary VM using VNC token from deleted VM
CVE-2014-2573
CVE-2014-2573
CVE-2013-0335
CVE-2013-0335
CVE-2013-1838
CVE-2013-1838
CVE-2014-0134
CVE-2014-0134
CVE-2013-7130
CVE-2013-7130
CVE-2015-2687
CVE-2015-2687
CVE-2012-3360
OpenStack Nova Directory traversal vulnerability
CVE-2012-3361
OpenStack Nova Arbitrary file injection/corruption through directory traversal issues
CVE-2012-3371
OpenStack Nova Scheduler denial of service through scheduler_hints
CVE-2012-2101
Openstack Compute (Nova) Denial of service via network request that triggers large number of iptables rules
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes