Debian has published security advisory DSA-6519-1 addressing CVE-2026-97149, an information disclosure vulnerability in the OpenStack Swift tempurl middleware. The flaw is rated medium severity, but do not let that rating lull you into a slow response cycle. TempURL is the mechanism that issues time-limited, HMAC-signed URLs granting anonymous access to otherwise protected objects in Swift object storage. When the component responsible for authorizing access to stored data has an information disclosure weakness, the practical risk is confidentiality loss across your entire object store — backups, documents, application payloads, and anything else sitting in Swift containers.
Debian has fixed the issue in the stable distribution (trixie / Debian 13) in package version 2.35.1-0+deb13u4. If you operate Swift proxy nodes on trixie — whether standalone object storage, part of an OpenStack cloud, or embedded in an appliance stack — you should treat this as a priority patch and follow it with TempURL secret rotation.
Technical Analysis
Affected Products and Versions
- Component: OpenStack Swift
tempurlmiddleware (part of the Swift proxy-server pipeline) - Platform: Debian 13 (trixie), stable distribution
- Vulnerable packages:
swift/swift-proxyand related Swift packages prior to the fixed build - Fixed version: 2.35.1-0+deb13u4
- CVE: CVE-2026-97149 (medium severity per Debian's assessment; no upstream CVSS vector was published with the advisory at time of writing)
How TempURL Works — and Why a Flaw Here Matters
The tempurl middleware sits in the Swift proxy pipeline (/etc/swift/proxy-server.conf, typically pipeline = ... tempurl ... proxy-server). It validates requests carrying temp_url_sig and temp_url_expires query parameters against an HMAC computed from a shared secret (the X-Account-Meta-Temp-URL-Key / X-Container-Meta-Temp-URL-Key metadata keys). A valid signature grants unauthenticated read — and optionally write — access to a specific object until the expiry timestamp.
An information disclosure vulnerability in this middleware classically manifests in one of several defender-relevant ways:
- Signature validation bypass or oracle behavior — differing responses or timing that let an attacker infer valid signatures or key material.
- Exposure of internal state — error paths, headers, or responses leaking HMAC inputs, key fragments, account/container metadata, or object inventory details that should be invisible to anonymous requesters.
- Expiry or method enforcement gaps — disclosed information enabling requests outside the intended time window or HTTP method scope.
Any of these translates to the same operational outcome: unauthorized parties reading objects from your Swift cluster without valid credentials. Because TempURL access is anonymous by design, abuse does not generate authentication failures — it looks like legitimate, successful object retrieval.
Exploitation Requirements and Status
- Exploitation requires network reachability to the Swift proxy endpoint (commonly TCP/443 or TCP/8080) and knowledge of an account/container/object path — which is itself the kind of information an info-leak can hand to an attacker.
- At the time of writing, there is no confirmed public proof-of-concept, no inclusion in the CISA Known Exploited Vulnerabilities catalog, and no reporting of in-the-wild exploitation tied to this CVE. That is an opportunity, not an excuse: medium-severity info-leaks in storage middleware are exactly the bugs that get quietly chained into data-theft campaigns after the advisory drops.
Detection & Response
Your primary telemetry source is the Swift proxy-server log (typically /var/log/swift/proxy-server.log or syslog, forwarded to your SIEM). Detection centers on three behaviors: (1) TempURL-signed requests from unexpected sources, (2) enumeration-style probing against object paths, and (3) error/signature-mismatch bursts indicating signature guessing or oracle probing.
Sigma Rules
---
title: OpenStack Swift TempURL Signed Request from Suspicious Source
id: 3f9a2c14-7b61-4e58-9d2a-5c8f1b0e6a31
status: experimental
description: Detects TempURL-signed object requests (temp_url_sig parameter) hitting the Swift proxy from external or untrusted sources. Following CVE-2026-97149 (Debian DSA-6519-1), signed anonymous access should be tightly monitored as exploitation of the tempurl middleware presents as successful anonymous GETs.
references:
- https://linuxsecurity.com/advisories/debian/debian-dsa-6519-1-swift
- https://attack.mitre.org/techniques/T1530/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.collection
- attack.t1530
logsource:
product: linux
service: swift
detection:
selection:
- 'temp_url_sig='
- 'temp_url_expires='
condition: selection
falsepositives:
- Legitimate pre-signed URL sharing workflows (CDN fetches, customer download links)
level: medium
---
title: OpenStack Swift Proxy Signature Mismatch Burst
id: 8c1e5d72-2a94-4f37-b6e0-9d4c3a1f7b52
status: experimental
description: Detects bursts of 401/403 responses on Swift proxy requests carrying TempURL parameters, consistent with signature guessing, HMAC oracle probing, or exploitation attempts against the tempurl middleware (CVE-2026-97149 / DSA-6519-1).
references:
- https://linuxsecurity.com/advisories/debian/debian-dsa-6519-1-swift
- https://attack.mitre.org/techniques/T1110/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.credential_access
- attack.t1110
logsource:
product: linux
service: swift
detection:
selection_sig:
- 'temp_url_sig='
selection_status:
- ' 401 '
- ' 403 '
condition: selection_sig and selection_status
falsepositives:
- Expired TempURL links used by legitimate clients after the expiry timestamp
level: high
---
title: OpenStack Swift Object Path Enumeration via Proxy Logs
id: 5b7d0f39-1c46-4a82-a391-2e8c6d9f0a44
status: experimental
description: Detects enumeration-style HEAD/GET probing across Swift account/container/object paths from a single source, including 404-heavy sequences that precede TempURL abuse. Relevant to post-disclosure recon against CVE-2026-97149.
references:
- https://linuxsecurity.com/advisories/debian/debian-dsa-6519-1-swift
- https://attack.mitre.org/techniques/T1083/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.discovery
- attack.t1083
logsource:
product: linux
service: swift
detection:
selection:
- 'HEAD /v1/'
- 'GET /v1/'
filter_status:
- ' 200 '
condition: selection and not filter_status
falsepositives:
- Health checks and monitoring probes (restrict by known probe user agents/IPs)
level: low
Microsoft Sentinel / Defender KQL
This query hunts Swift proxy events ingested via Syslog/CEF for TempURL abuse patterns — signed anonymous access, signature failures, and enumeration bursts from a single source within a 10-minute window.
let Lookback = 24h;
let Window = 10m;
Syslog
| where TimeGenerated > ago(Lookback)
| where ProcessName has_any ("proxy-server", "swift") or SyslogMessage has "temp_url"
| extend IsSigned = SyslogMessage has "temp_url_sig=",
IsDenied = SyslogMessage has_any (" 401 ", " 403 "),
IsMiss = SyslogMessage has " 404 "
| summarize SignedRequests = countif(IsSigned),
DeniedRequests = countif(IsDenied),
MissRequests = countif(IsMiss),
SamplePaths = make_set_if(SyslogMessage, IsSigned or IsDenied, 10)
by Computer, HostIP, bin(TimeGenerated, Window)
| where SignedRequests > 50 or DeniedRequests > 20 or (MissRequests > 100 and SignedRequests > 0)
| order by DeniedRequests desc;
Tune the thresholds against your baseline — a storage cluster serving pre-signed download links at volume will legitimately generate thousands of signed requests. The high-fidelity signal is denied signed requests and enumeration preceding signed access from the same source.
Velociraptor VQL
Use this hunt artifact to pull TempURL activity directly from on-disk Swift proxy logs on Debian trixie nodes, even where SIEM forwarding gaps exist.
-- Hunt for TempURL-signed requests and signature failures in Swift proxy logs
LET lines <= SELECT FullPath, Line
FROM parse_lines(
filename=glob('/var/log/swift/proxy-server*.log', '/var/log/syslog*'),
accessor='file'
)
WHERE Line =~ 'temp_url_sig'
SELECT FullPath AS LogFile,
Line AS RawEvent,
count() AS Hits
FROM lines
WHERE RawEvent =~ 'temp_url_sig='
GROUP BY LogFile, RawEvent
LIMIT 500
Remediation and Verification Script
Run this on Debian 13 (trixie) Swift proxy and storage nodes. It checks the installed version against the fixed build, applies the update, restarts the proxy, and flags TempURL key metadata for rotation.
#!/bin/bash
# CVE-2026-97149 / DSA-6519-1 — Swift tempurl remediation verifier (Debian 13 trixie)
FIXED_VER="2.35.1-0+deb13u4"
echo "[*] Checking installed swift package version..."
INSTALLED=$(dpkg-query -W -f='${Version}' swift 2>/dev/null)
if [ -z "$INSTALLED" ]; then
echo "[-] swift package not installed on this host. Nothing to do."
exit 0
fi
echo "[*] Installed: $INSTALLED | Fixed: $FIXED_VER"
if dpkg --compare-versions "$INSTALLED" lt "$FIXED_VER"; then
echo "[!] VULNERABLE — applying DSA-6519-1 update"
apt-get update
apt-get install --only-upgrade -y swift swift-proxy swift-account swift-container swift-object
echo "[*] Restarting Swift proxy services..."
systemctl restart swift-proxy 2>/dev/null || swift-init proxy restart
NEW_VER=$(dpkg-query -W -f='${Version}' swift)
dpkg --compare-versions "$NEW_VER" ge "$FIXED_VER" && echo "[+] PATCHED: $NEW_VER" || echo "[!] PATCH FAILED: still $NEW_VER"
else
echo "[+] Already patched: $INSTALLED"
fi
# Post-patch hygiene: TempURL shared secrets should be rotated after any tempurl CVE
echo "[*] Rotate TempURL keys (example — adjust account/container names):"
echo " swift post -m 'Temp-Url-Key:<new-strong-secret>'"
echo " swift post -m 'Temp-Url-Key-2:<new-strong-secret>' # dual-key for zero-downtime rollover"
echo "[*] Review proxy logs for pre-patch signed access: grep 'temp_url_sig' /var/log/swift/proxy-server.log"
Remediation
- Patch immediately. Upgrade all Swift packages on Debian 13 (trixie) to 2.35.1-0+deb13u4 or later via
apt-get update && apt-get install --only-upgrade swift swift-proxy swift-account swift-container swift-object. Reference: DSA-6519-1 via LinuxSecurity and the Debian Security Tracker entry for CVE-2026-97149. - Rotate TempURL secrets. Because this is an information disclosure in the middleware that validates HMAC-signed URLs, assume key material or signature-validation integrity may have been observable pre-patch. Rotate
X-Account-Meta-Temp-URL-Key(and container-level keys). Use the two-key mechanism (Temp-Url-Key/Temp-Url-Key-2) to roll over without invalidating in-flight URLs. - Invalidate outstanding TempURLs. Any pre-signed URLs minted before the patch carry the old trust context. Rotate keys to kill them, or explicitly re-issue URLs for legitimate workflows.
- Restrict proxy exposure. If your Swift proxy is reachable beyond its intended client base, enforce network ACLs / security groups limiting access to known consumers. TempURL abuse requires proxy reachability — shrinking that surface shrinks the blast radius.
- Audit retroactively. Search proxy logs for
temp_url_sig=requests predating the patch from unfamiliar source IPs, and for 401/403 bursts against signed URLs. Successful anonymous GETs on sensitive containers are your indicator of materialized impact. - Baseline and alert. Deploy the Sigma/KQL detections above with thresholds tuned to your environment's legitimate pre-signed URL volume, and alert on signature-failure bursts as a standing control.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.