Keystone
Vendor:
First CVE: Jul 31, 2012 · Active for 13 years
46
Total CVEs
More Total CVEs than 97% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Keystone over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 31, 2012
13 years ago
Most Recent CVE
May 28, 2026
57 days ago
CVE Severity & Scoring
Keystone46 CVEs
59%
37%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network22 (47.8%)
Unknown24 (52.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (28.3%)
High9 (19.6%)
Unknown24 (52.2%)
User Interaction
None22 (47.8%)
Unknown24 (52.2%)
Required0 (0.0%)
Privileges Required
Low15 (32.6%)
High1 (2.2%)
None6 (13.0%)
Unknown24 (52.2%)
Top CVEs
Signals from CVEs in this product scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-43001HIGH An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the projec | May 1, 2026 | 8.0 | 35 | NO | NO |
CVE-2026-43000HIGH An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project | May 28, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-42999HIGH An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enfo | May 28, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-42998HIGH An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication | May 28, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-44394HIGH An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued tok | May 28, 2026 | 8.1 | 29 | NO | NO |
CVE-2019-19687HIGH OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credent | Dec 9, 2019 | 8.8 | 27 | NO | NO |
CVE-2026-40683HIGH In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False ( | Apr 14, 2026 | 7.7 | 26 | NO | NO |
CVE-2025-65073HIGH OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization. | Nov 17, 2025 | 7.5 | 24 | NO | NO |
CVE-2021-38155HIGH OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to | Aug 6, 2021 | 7.5 | 24 | NO | NO |
CVE-2012-1572HIGH OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space | Nov 12, 2019 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (46 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (46 CVEs).
Media Mentions
Signals from CVEs in this product scope (46 CVEs).
Top CNAs Publishing CVEs For Keystone
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| juno-2 | 3 | 4.9 | 1.5% | 0 | 0 |
| juno-1 | 3 | 4.9 | 1.5% | 0 | 0 |
| 29.0.0 | 1 | 5.3 | 0.2% | 0 | 0 |
| 28.0.0 | 1 | 5.3 | 0.2% | 0 | 0 |
| 27.0.0 | 1 | 5.3 | 0.2% | 0 | 0 |
| 2014.1.2 | 3 | 4.9 | 1.5% | 0 | 0 |
| 2014.1 | 3 | 4.9 | 1.5% | 0 | 0 |
| 2013.2.3 | 1 | 7.8 | 3.2% | 0 | 0 |
| 2013.2.2 | 2 | 6.4 | 2.3% | 0 | 0 |
| 2013.2.1 | 1 | 7.8 | 3.2% | 0 | 0 |
| 2013.2 | 1 | 7.8 | 3.2% | 0 | 0 |
| 2013.1.4 | 1 | 5.0 | 1.4% | 0 | 0 |
| 2013.1.3 | 3 | 5.9 | 2.4% | 0 | 0 |
| 2013.1.2 | 3 | 5.9 | 2.4% | 0 | 0 |
| 2013.1.1 | 4 | 5.0 | 2.0% | 0 | 0 |
| 2013.1 | 6 | 5.8 | 2.4% | 0 | 0 |
| 2013 | 1 | 5.9 | 1.0% | 0 | 0 |
| 2012.2.4 | 1 | 5.0 | 2.7% | 0 | 0 |
| 2012.2.3 | 1 | 5.0 | 2.7% | 0 | 0 |
| 2012.2.2 | 1 | 5.0 | 2.7% | 0 | 0 |