)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"change_message_id":"17328bd9c24f6e2f6f633faa26ae634bcd907717","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"e9830332_21e80b8c","updated":"2026-08-13 17:11:19.000000000","message":"Affected versions string and URLs are correct.","commit_id":"0d3d795af04af5d37df224609549ba1db0efdb25"}],"ossa/OSSA-2026-035.yaml":[{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"6dc8117417b3f69e931220c8270914e52331a034","unresolved":true,"context_lines":[{"line_number":8,"context_line":"  Chen YuXiang with the Institute of Computing Technology, Chinese Academy of"},{"line_number":9,"context_line":"  Sciences, reported a vulnerability in Octavia quality of service (QoS) policy"},{"line_number":10,"context_line":"  authorization. By associating another project\u0027s QoS policy with an amphora,"},{"line_number":11,"context_line":"  an authenticated user may prevent deletion of that policy. All Octavia"},{"line_number":12,"context_line":"  deployments are affected."},{"line_number":13,"context_line":""},{"line_number":14,"context_line":"affected-products:"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"7591275d_449b5969","line":11,"range":{"start_line":11,"start_character":53,"end_line":11,"end_character":59},"updated":"2026-08-13 17:13:10.000000000","message":"of the load balancer (amphora)?","commit_id":"0d3d795af04af5d37df224609549ba1db0efdb25"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"828e37e710dafc7e283d38472aadbffc6781151d","unresolved":false,"context_lines":[{"line_number":8,"context_line":"  Chen YuXiang with the Institute of Computing Technology, Chinese Academy of"},{"line_number":9,"context_line":"  Sciences, reported a vulnerability in Octavia quality of service (QoS) policy"},{"line_number":10,"context_line":"  authorization. By associating another project\u0027s QoS policy with an amphora,"},{"line_number":11,"context_line":"  an authenticated user may prevent deletion of that policy. All Octavia"},{"line_number":12,"context_line":"  deployments are affected."},{"line_number":13,"context_line":""},{"line_number":14,"context_line":"affected-products:"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"1c181241_4e7e5c87","line":11,"range":{"start_line":11,"start_character":53,"end_line":11,"end_character":59},"in_reply_to":"7591275d_449b5969","updated":"2026-08-13 17:17:42.000000000","message":"ty for noting this in #openstack-security..\n\nit\u0027s the deletion of the qos policy that\u0027s blocked.","commit_id":"0d3d795af04af5d37df224609549ba1db0efdb25"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"6dc8117417b3f69e931220c8270914e52331a034","unresolved":false,"context_lines":[{"line_number":22,"context_line":"  - name: Chen YuXiang"},{"line_number":23,"context_line":"    affiliation: Institute of Computing Technology, Chinese Academy of Sciences"},{"line_number":24,"context_line":"    reported:"},{"line_number":25,"context_line":"      - PENDING"},{"line_number":26,"context_line":""},{"line_number":27,"context_line":"issues:"},{"line_number":28,"context_line":"  links:"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"1516c52b_56c29708","line":25,"range":{"start_line":25,"start_character":8,"end_line":25,"end_character":15},"updated":"2026-08-13 17:13:10.000000000","message":"(kinda stopped adding this for pending ones)","commit_id":"0d3d795af04af5d37df224609549ba1db0efdb25"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"6dc8117417b3f69e931220c8270914e52331a034","unresolved":false,"context_lines":[{"line_number":42,"context_line":"    - https://review.opendev.org/1000296"},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"notes:"},{"line_number":45,"context_line":"  - A CVE assignment was requested from MITRE on 2026-08-05 (request 2079027);"},{"line_number":46,"context_line":"    this advisory will be updated with the ID in an errata publication once it"},{"line_number":47,"context_line":"    becomes available."}],"source_content_type":"text/x-yaml","patch_set":1,"id":"2ef8b643_26f0391d","line":45,"range":{"start_line":45,"start_character":60,"end_line":45,"end_character":78},"updated":"2026-08-13 17:13:10.000000000","message":"(this isn\u0027t a CAN-ID, but, future reference, MITRE asks not to quote CAN-IDs)","commit_id":"0d3d795af04af5d37df224609549ba1db0efdb25"}]}
