{"id":"GHSA-whqr-fgm5-x77q","summary":"OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token","details":"An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected.","aliases":["CVE-2026-44394","PYSEC-2026-603"],"modified":"2026-07-17T21:13:33.270277465Z","published":"2026-05-28T21:32:02Z","database_specific":{"github_reviewed_at":"2026-07-02T17:44:27Z","nvd_published_at":"2026-05-28T19:16:38Z","cwe_ids":["CWE-863"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44394"},{"type":"WEB","url":"https://bugs.launchpad.net/keystone/+bug/2150379"},{"type":"PACKAGE","url":"https://github.com/openstack/keystone"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/keystone/PYSEC-2026-603.yaml"},{"type":"WEB","url":"https://security.openstack.org/ossa/OSSA-2026-015.html"}],"affected":[{"package":{"name":"keystone","ecosystem":"PyPI","purl":"pkg:pypi/keystone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14.0.0"},{"fixed":"27.0.2"}]}],"versions":["14.0.0","14.0.1","14.1.0","14.2.0","15.0.0","15.0.0.0rc1","15.0.0.0rc2","15.0.1","16.0.0","16.0.0.0rc1","16.0.0.0rc2","16.0.1","16.0.2","17.0.0","17.0.0.0rc1","17.0.0.0rc2","17.0.1","18.0.0","18.0.0.0rc1","18.1.0","19.0.0","19.0.0.0rc1","19.0.0.0rc2","19.0.1","20.0.0","20.0.0.0rc1","20.0.1","21.0.0","21.0.0.0rc1","21.0.1","22.0.0","22.0.0.0rc1","22.0.1","22.0.2","23.0.0","23.0.0.0rc1","23.0.1","23.0.2","24.0.0","24.0.0.0rc1","24.1.0","25.0.0","25.0.0.0rc1","26.0.0","26.0.0.0rc1","26.1.0","26.1.1","27.0.0","27.0.0.0rc1","27.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-whqr-fgm5-x77q/GHSA-whqr-fgm5-x77q.json"}},{"package":{"name":"keystone","ecosystem":"PyPI","purl":"pkg:pypi/keystone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"28.0.0"},{"fixed":"28.0.2"}]}],"versions":["28.0.0","28.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-whqr-fgm5-x77q/GHSA-whqr-fgm5-x77q.json"}},{"package":{"name":"keystone","ecosystem":"PyPI","purl":"pkg:pypi/keystone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"29.0.0"},{"fixed":"29.0.2"}]}],"versions":["29.0.0","29.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-whqr-fgm5-x77q/GHSA-whqr-fgm5-x77q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L"}]}