)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"d8586c8cd7c400cdfd0d1e96e1894a51ca180beb","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"9043449b_5a496b91","updated":"2026-09-18 07:00:05.000000000","message":"LGTM","commit_id":"a05855e9feb2cbefef61ba3491a190bf55e1f016"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"2e7a4bef7d90bc22c987ab9f4dc6757518510760","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"d1266437_e69837da","updated":"2026-09-17 22:28:19.000000000","message":"My +2 is pending review and approval by project cores","commit_id":"a05855e9feb2cbefef61ba3491a190bf55e1f016"},{"author":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"change_message_id":"12ba47d285ff6ca3edf6ee7a3d97e483afc413fd","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"1438e4d7_3243df33","updated":"2026-09-18 13:56:33.000000000","message":"Typo noted inline; the other comments are just suggestions that you can take or leave.","commit_id":"a05855e9feb2cbefef61ba3491a190bf55e1f016"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"9577bd03cd6ddca355369919441ef42dbb72c439","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"d26881fc_1787687a","updated":"2026-09-21 14:17:06.000000000","message":"LGTM","commit_id":"9ebda12b6f9c09436adf7f15bc9fabd17a4f23e7"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"cdc3918527f8e1fa9388752d163f871578442a51","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"99a05b44_4b156b04","updated":"2026-09-18 21:58:21.000000000","message":"Thank you for the reviews; made some more changes here and set the date to Monday/Sep 21st 2026 - please let me know if there are more changes to be made","commit_id":"9ebda12b6f9c09436adf7f15bc9fabd17a4f23e7"},{"author":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"change_message_id":"3819d5050bb449962a4a87a6027b237a593e1e45","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"0a8b6a37_09879d43","updated":"2026-09-21 16:00:04.000000000","message":"Revisions LGTM.","commit_id":"24ca8e04fc1285b4973ac7023ef1fd8d9d848992"}],"ossa/OSSA-2026-039.yaml":[{"author":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"change_message_id":"12ba47d285ff6ca3edf6ee7a3d97e483afc413fd","unresolved":true,"context_lines":[{"line_number":14,"context_line":"  who owns a load balancer managed by OpenStack Octavia\u0027s Amphora"},{"line_number":15,"context_line":"  provider to inject arbitrary HAProxy configuration directives."},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"  A reporter participating in the Infomaniak bug bounty program"},{"line_number":18,"context_line":"  demonstrated that these flaws can be exploited to execute arbitrary"},{"line_number":19,"context_line":"  commands as root on the provider-managed amphora, to disclose other"},{"line_number":20,"context_line":"  tenants\u0027 TLS private keys and certificates and the deployment"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"bddca209_ebe9acdc","line":17,"range":{"start_line":17,"start_character":2,"end_line":17,"end_character":12},"updated":"2026-09-18 13:56:33.000000000","message":"Maybe: \"Subsequently, an independent reporter ...\"","commit_id":"a05855e9feb2cbefef61ba3491a190bf55e1f016"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"cdc3918527f8e1fa9388752d163f871578442a51","unresolved":false,"context_lines":[{"line_number":14,"context_line":"  who owns a load balancer managed by OpenStack Octavia\u0027s Amphora"},{"line_number":15,"context_line":"  provider to inject arbitrary HAProxy configuration directives."},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"  A reporter participating in the Infomaniak bug bounty program"},{"line_number":18,"context_line":"  demonstrated that these flaws can be exploited to execute arbitrary"},{"line_number":19,"context_line":"  commands as root on the provider-managed amphora, to disclose other"},{"line_number":20,"context_line":"  tenants\u0027 TLS private keys and certificates and the deployment"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"d4dd7076_a6ac3c4b","line":17,"range":{"start_line":17,"start_character":2,"end_line":17,"end_character":12},"in_reply_to":"bddca209_ebe9acdc","updated":"2026-09-18 21:58:21.000000000","message":"Done","commit_id":"a05855e9feb2cbefef61ba3491a190bf55e1f016"},{"author":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"change_message_id":"12ba47d285ff6ca3edf6ee7a3d97e483afc413fd","unresolved":true,"context_lines":[{"line_number":25,"context_line":""},{"line_number":26,"context_line":"affected-products:"},{"line_number":27,"context_line":"  - product: octavia"},{"line_number":28,"context_line":"    version: \u0027\u003e\u003d0.8.0 \u003c16.1.0, \u003d\u003d17.0.0, \u003d\u003d18.0.0\u0027"},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"vulnerabilities:"},{"line_number":31,"context_line":"  - cve-id: CVE-2026-pending"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"36a3d4cf_be309d50","line":28,"updated":"2026-09-18 13:56:33.000000000","message":"affected version string checks out.  kind of weird that there\u0027s a release for stable/2025.1 with the fix, but none of the other stable branches (but maybe that was proposed by the release team to prepare for 2025.1 going to unmaintained status in a few weeks)","commit_id":"a05855e9feb2cbefef61ba3491a190bf55e1f016"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"d8586c8cd7c400cdfd0d1e96e1894a51ca180beb","unresolved":true,"context_lines":[{"line_number":25,"context_line":""},{"line_number":26,"context_line":"affected-products:"},{"line_number":27,"context_line":"  - product: octavia"},{"line_number":28,"context_line":"    version: \u0027\u003e\u003d0.8.0 \u003c16.1.0, \u003d\u003d17.0.0, \u003d\u003d18.0.0\u0027"},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"vulnerabilities:"},{"line_number":31,"context_line":"  - cve-id: CVE-2026-pending"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"6f2ff206_d36b0a3f","line":28,"range":{"start_line":28,"start_character":14,"end_line":28,"end_character":21},"updated":"2026-09-18 07:00:05.000000000","message":"if that matters, the tls_ciphers features were added in 6.0.0","commit_id":"a05855e9feb2cbefef61ba3491a190bf55e1f016"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"cdc3918527f8e1fa9388752d163f871578442a51","unresolved":true,"context_lines":[{"line_number":25,"context_line":""},{"line_number":26,"context_line":"affected-products:"},{"line_number":27,"context_line":"  - product: octavia"},{"line_number":28,"context_line":"    version: \u0027\u003e\u003d0.8.0 \u003c16.1.0, \u003d\u003d17.0.0, \u003d\u003d18.0.0\u0027"},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"vulnerabilities:"},{"line_number":31,"context_line":"  - cve-id: CVE-2026-pending"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"f6dc8b98_06931d67","line":28,"in_reply_to":"36a3d4cf_be309d50","updated":"2026-09-18 21:58:21.000000000","message":"Not weird :) This wasn\u0027t considered worthy of a release. but will be now. I\u0027ve requested a security release for the other branches.","commit_id":"a05855e9feb2cbefef61ba3491a190bf55e1f016"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"cdc3918527f8e1fa9388752d163f871578442a51","unresolved":false,"context_lines":[{"line_number":25,"context_line":""},{"line_number":26,"context_line":"affected-products:"},{"line_number":27,"context_line":"  - product: octavia"},{"line_number":28,"context_line":"    version: \u0027\u003e\u003d0.8.0 \u003c16.1.0, \u003d\u003d17.0.0, \u003d\u003d18.0.0\u0027"},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"vulnerabilities:"},{"line_number":31,"context_line":"  - cve-id: CVE-2026-pending"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"69416256_ca7a9c6f","line":28,"range":{"start_line":28,"start_character":14,"end_line":28,"end_character":21},"in_reply_to":"6f2ff206_d36b0a3f","updated":"2026-09-18 21:58:21.000000000","message":"ack, this versioning applies for the redirect_url/redirect_prefix; but i\u0027ve clarified in a note below.","commit_id":"a05855e9feb2cbefef61ba3491a190bf55e1f016"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"b59860071af1424e68757fe3f1e9bcb823251d0a","unresolved":true,"context_lines":[{"line_number":35,"context_line":"  - name: Chen YuXiang"},{"line_number":36,"context_line":"    affiliation: Institute of Computing Technology, Chinese Academy of Sciences"},{"line_number":37,"context_line":"  - name: \u0027[bug bounty reporter - name pending]\u0027"},{"line_number":38,"context_line":"    affiliation: Infomaniak bug bounty program"},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"issues:"},{"line_number":41,"context_line":"  links:"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"8809b08f_7684116d","line":38,"updated":"2026-09-17 22:28:05.000000000","message":"We should provide a link to this program or a note it\u0027s not VMT official if this ends up being the affiliation. Ideally this is actually the place that person reps","commit_id":"a05855e9feb2cbefef61ba3491a190bf55e1f016"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"cdc3918527f8e1fa9388752d163f871578442a51","unresolved":true,"context_lines":[{"line_number":35,"context_line":"  - name: Chen YuXiang"},{"line_number":36,"context_line":"    affiliation: Institute of Computing Technology, Chinese Academy of Sciences"},{"line_number":37,"context_line":"  - name: \u0027[bug bounty reporter - name pending]\u0027"},{"line_number":38,"context_line":"    affiliation: Infomaniak bug bounty program"},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"issues:"},{"line_number":41,"context_line":"  links:"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"eb318833_ddce418f","line":38,"in_reply_to":"8809b08f_7684116d","updated":"2026-09-18 21:58:21.000000000","message":"ack; I\u0027m hoping @thomas@goirand.fr will update us and we\u0027ll get rid of this placeholder prior to publication.","commit_id":"a05855e9feb2cbefef61ba3491a190bf55e1f016"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"d907d33e7d8949a74c2733ce01a1bb06fb3ec8f9","unresolved":false,"context_lines":[{"line_number":35,"context_line":"  - name: Chen YuXiang"},{"line_number":36,"context_line":"    affiliation: Institute of Computing Technology, Chinese Academy of Sciences"},{"line_number":37,"context_line":"  - name: \u0027[bug bounty reporter - name pending]\u0027"},{"line_number":38,"context_line":"    affiliation: Infomaniak bug bounty program"},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"issues:"},{"line_number":41,"context_line":"  links:"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"345a36d2_a84c41ae","line":38,"in_reply_to":"eb318833_ddce418f","updated":"2026-09-21 15:38:13.000000000","message":"We got the reporter username, and I dropped mentions of the bug bounty program. Those mentions are in the launchpad bug. Thank you @thomas@goirand.fr!","commit_id":"a05855e9feb2cbefef61ba3491a190bf55e1f016"},{"author":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"change_message_id":"12ba47d285ff6ca3edf6ee7a3d97e483afc413fd","unresolved":true,"context_lines":[{"line_number":44,"context_line":"    - https://launchpad.net/bugs/2162103"},{"line_number":45,"context_line":""},{"line_number":46,"context_line":"reviews:"},{"line_number":47,"context_line":"  2027.1/hibiscus:"},{"line_number":48,"context_line":"    - https://review.opendev.org/999553"},{"line_number":49,"context_line":"    - https://review.opendev.org/999555"},{"line_number":50,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":1,"id":"384074df_9f48af01","line":47,"range":{"start_line":47,"start_character":2,"end_line":47,"end_character":18},"updated":"2026-09-18 13:56:33.000000000","message":"should be 2026.2/hibiscus","commit_id":"a05855e9feb2cbefef61ba3491a190bf55e1f016"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"cdc3918527f8e1fa9388752d163f871578442a51","unresolved":false,"context_lines":[{"line_number":44,"context_line":"    - https://launchpad.net/bugs/2162103"},{"line_number":45,"context_line":""},{"line_number":46,"context_line":"reviews:"},{"line_number":47,"context_line":"  2027.1/hibiscus:"},{"line_number":48,"context_line":"    - https://review.opendev.org/999553"},{"line_number":49,"context_line":"    - https://review.opendev.org/999555"},{"line_number":50,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":1,"id":"69d63873_a56fe032","line":47,"range":{"start_line":47,"start_character":2,"end_line":47,"end_character":18},"in_reply_to":"384074df_9f48af01","updated":"2026-09-18 21:58:21.000000000","message":"Done","commit_id":"a05855e9feb2cbefef61ba3491a190bf55e1f016"},{"author":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"change_message_id":"12ba47d285ff6ca3edf6ee7a3d97e483afc413fd","unresolved":true,"context_lines":[{"line_number":64,"context_line":"  - \u0027Two changes are required on each branch: one fixes the"},{"line_number":65,"context_line":"    ``tls_ciphers`` fields and one fixes the L7 policy redirect"},{"line_number":66,"context_line":"    fields.\u0027"},{"line_number":67,"context_line":""},{"line_number":68,"context_line":"  - \u0027Only the Amphora provider driver is affected. Deployments that"},{"line_number":69,"context_line":"    use a different provider driver do not render tenant input into"},{"line_number":70,"context_line":"    an HAProxy configuration and are not affected.\u0027"},{"line_number":71,"context_line":""},{"line_number":72,"context_line":"  - \u0027These issues were originally triaged as a low-severity hardening"},{"line_number":73,"context_line":"    opportunity and the fixes were developed and merged in public."}],"source_content_type":"text/x-yaml","patch_set":1,"id":"b7308ef7_a99d78de","line":70,"range":{"start_line":67,"start_character":0,"end_line":70,"end_character":51},"updated":"2026-09-18 13:56:33.000000000","message":"Instead of making this a note, I suggest replacing the paragraph at line 24 with this text.  It will also move the note at line 72 higher in the list of notes, which I think is important because it explains how this OSSA is being handled.","commit_id":"a05855e9feb2cbefef61ba3491a190bf55e1f016"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"cdc3918527f8e1fa9388752d163f871578442a51","unresolved":false,"context_lines":[{"line_number":64,"context_line":"  - \u0027Two changes are required on each branch: one fixes the"},{"line_number":65,"context_line":"    ``tls_ciphers`` fields and one fixes the L7 policy redirect"},{"line_number":66,"context_line":"    fields.\u0027"},{"line_number":67,"context_line":""},{"line_number":68,"context_line":"  - \u0027Only the Amphora provider driver is affected. Deployments that"},{"line_number":69,"context_line":"    use a different provider driver do not render tenant input into"},{"line_number":70,"context_line":"    an HAProxy configuration and are not affected.\u0027"},{"line_number":71,"context_line":""},{"line_number":72,"context_line":"  - \u0027These issues were originally triaged as a low-severity hardening"},{"line_number":73,"context_line":"    opportunity and the fixes were developed and merged in public."}],"source_content_type":"text/x-yaml","patch_set":1,"id":"2a7b529b_3109e0a1","line":70,"range":{"start_line":67,"start_character":0,"end_line":70,"end_character":51},"in_reply_to":"b7308ef7_a99d78de","updated":"2026-09-18 21:58:21.000000000","message":"Good point. Done..","commit_id":"a05855e9feb2cbefef61ba3491a190bf55e1f016"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"4559ff1533a5c2c4544426df4a4c81713f6c57ed","unresolved":true,"context_lines":[{"line_number":16,"context_line":""},{"line_number":17,"context_line":"  Subsequently, an independent reporter, \"Rolix\", demonstrated that"},{"line_number":18,"context_line":"  these flaws can be exploited to execute arbitrary commands as root"},{"line_number":19,"context_line":"  on the provider-managed amphora, to disclose other tenants\u0027 TLS"},{"line_number":20,"context_line":"  private keys and certificates and the deployment heartbeat key"},{"line_number":21,"context_line":"  stored on the amphora, and to reach the control-plane network to"},{"line_number":22,"context_line":"  which the amphora is attached."},{"line_number":23,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"cf01a897_6199aa40","line":20,"range":{"start_line":19,"start_character":47,"end_line":20,"end_character":31},"updated":"2026-09-22 05:29:25.000000000","message":"not sure if it\u0027s accurate, an amphora only contains the keys and certificates of the owner of the LB (the attacker)","commit_id":"24ca8e04fc1285b4973ac7023ef1fd8d9d848992"}]}
