SCA: security update for oslo.messaging (GHSA-76qh-xr7q-h39m)

high Tenable Self-Hosted Container Security Plugin ID 446645

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ
driver does not perform TLS hostname verification when connecting to the message broker. When ssl_ca_file
is configured, the driver enables certificate chain validation but does not pass the expected broker
hostname into the underlying TLS stack. Any certificate signed by the deployment CA is accepted regardless
of hostname, allowing an attacker who can intercept control-plane traffic to impersonate the RabbitMQ
broker and perform a man-in-the-middle attack on RPC and notification traffic. All OpenStack services
using oslo.messaging with RabbitMQ over TLS are affected. (CVE-2026-44393)

Solution

There is no known solution at this time.

See Also

https://github.com/advisories/GHSA-76qh-xr7q-h39m

Plugin Details

Severity: High

ID: 446645

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/31/2026

Updated: 8/31/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.58

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.1

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-44393

CVSS v3

Risk Factor: High

Base Score: 7.4

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/4/2026

Vulnerability Publication Date: 6/4/2026

Reference Information

CVE: CVE-2026-44393