Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Apply a call-site guard in getPreferredLang() that counts both '-' and '_' separators and short-circuits to the English fallback when the total exceeds a small ceiling (e.g., 32). Alternatively, limit Accept-Language header size at a reverse proxy or WAF layer to 4 KiB or less.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass of the CVE-2022-32149 mitigation exists: the upstream guard counts only '-' characters but the internal BCP 47 scanner aliases '_' to '-' after the guard check. An unauthenticated attacker can send a crafted Accept-Language header using '_' separators to trigger quadratic-time parsing, consuming excessive CPU and denying authentication to all cluster users. | |
| Title | Openshift/oauth-server: openshift/oauth-server: quadratic-time dos via accept-language header underscore bypass on unauthenticated login endpoints | |
| First Time appeared |
Redhat
Redhat openshift |
|
| Weaknesses | CWE-407 | |
| CPEs | cpe:/a:redhat:openshift:4 | |
| Vendors & Products |
Redhat
Redhat openshift |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-01T17:05:39.937Z
Reserved: 2026-05-29T13:24:26.096Z
Link: CVE-2026-49329
Updated: 2026-09-01T17:05:28.400Z
Status : Awaiting Analysis
Published: 2026-09-01T16:16:57.760
Modified: 2026-09-01T21:03:04.987
Link: CVE-2026-49329
OpenCVE Enrichment
Updated: 2026-09-02T00:00:06Z