External Control of File Name or Path Affecting nova package, versions [,30.3.0)[31.0.0.0rc1,31.3.0)[32.0.0.0rc1,32.2.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.02% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-NOVA-15325681
  • published22 Feb 2026
  • disclosed17 Feb 2026
  • creditDan Smith

Introduced: 17 Feb 2026

CVE-2026-24708  (opens in a new tab)
CWE-73  (opens in a new tab)

How to fix?

Upgrade nova to version 30.3.0, 31.3.0, 32.2.0 or higher.

Overview

nova is an OpenStack Nova provides a cloud computing fabric controller, supporting a wide variety of compute technologies, including: libvirt (KVM, Xen, LXC and more), Hyper-V, VMware, XenServer, OpenStack Ironic and PowerVM.

Affected versions of this package are vulnerable to External Control of File Name or Path via unconstrained handling of disk image formats when invoking qemu-img. An attacker can overwrite arbitrary files on the compute host with the privileges of the Nova service by crafting a malicious QCOW2 header on an ephemeral or root disk and triggering destructive behavior during instance operations such as resize.

CVSS Base Scores

version 4.0
version 3.1