← Vulnerability feed

Vulnerability record · CVE-2013-4155 · published 20 August 2013

CVE-2013-4155: Openstack folsom memory buffer overflow vulnerability

Openstack · Folsom

OpenStack Swift before 1.9.1 in Folsom, Grizzly, and Havana allows authenticated users to cause a denial of service ("superfluous" tombstone consumption and Swift cluster slowdown) via a DELETE request with a timestamp that is older than expected.

4.0 CVSS 2.0 Medium EPSS 1.7% · top 24.1% CWE-119 · Memory buffer overflow
4.0CVSS 2.0 base score
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

OpenStack Swift before 1.9.1 in Folsom, Grizzly, and Havana allows authenticated users to cause a denial of service ("superfluous" tombstone consumption and Swift cluster slowdown) via a DELETE request with a timestamp that is older than expected.

AV:N/AC:L/Au:S/C:N/I:N/A:P

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-4155 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-16613Openstack swauth improper authentication vulnerabilityAn issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and …EPSS 8.4%9.8CVE-2012-4406Openstack swift deserialization of untrusted data vulnerabilityOpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memca…EPSS 6.6%8.8CVE-2013-0261Openstack essex link following vulnerabilityA flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This …EPSS 0.34%7.6CVE-2013-0335Openstack essex insufficient session expiration vulnerabilityOpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circu…EPSS 2.1%7.5CVE-2016-0738Openstack swift vulnerabilityOpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows …EPSS 3.9%7.5CVE-2016-0737Openstack swift vulnerabilityOpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service …EPSS 3.8%7.5CVE-2013-2161Openstack folsom code injection vulnerabilityXML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift r…EPSS 1.9%7.1CVE-2026-49017Openstack swift vulnerabilityIn OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The S…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2013-4155), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.