-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 15 Jan 2026 08:57:22 +0100 Source: python-keystonemiddleware Architecture: source Version: 10.9.0-2+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: Debian OpenStack <team+openstack@tracker.debian.org> Changed-By: Thomas Goirand <zigo@debian.org> Closes: 1125680 Changes: python-keystonemiddleware (10.9.0-2+deb13u1) trixie-security; urgency=medium . * CVE-2026-22797 / OSSA-2026-001: privilege escalation via spoofed identity headers. Applied upstream patch: Fix privilege escalation via spoofed identity headers (Closes: #1125680). Checksums-Sha1: 0af394e36073f6ea98e99da1a385148cb6802597 3183 python-keystonemiddleware_10.9.0-2+deb13u1.dsc d1c46de69074d5697558a0e95aae5b185b6ec3a5 148388 python-keystonemiddleware_10.9.0.orig.tar.xz 762d2343d68004717c841064d37f0be291ca69fd 7308 python-keystonemiddleware_10.9.0-2+deb13u1.debian.tar.xz 86bf21e8e6770dbcbcb5e117a2fb9e01cc1588bb 19290 python-keystonemiddleware_10.9.0-2+deb13u1_amd64.buildinfo Checksums-Sha256: c982e4dabcb83013261042c4547a925508a84b680e1b4140e73c28d28d58c411 3183 python-keystonemiddleware_10.9.0-2+deb13u1.dsc 25739e8ca7e4bd3ccbe2d8d51517be7fb41e8268f3c98ac1600a2a70e40ce3ee 148388 python-keystonemiddleware_10.9.0.orig.tar.xz 9731209fb403dc2ac5e3b57a8ab1ca260d9f5d6963627c475daf425f4f77aa89 7308 python-keystonemiddleware_10.9.0-2+deb13u1.debian.tar.xz 7844984104c8efbfa93a8012c784c4a998cc75246f92b2589aaae7de6f213e64 19290 python-keystonemiddleware_10.9.0-2+deb13u1_amd64.buildinfo Files: 63f47829ece86fcb6522e93adc867903 3183 python optional python-keystonemiddleware_10.9.0-2+deb13u1.dsc 6eddfd1ed4c6430450b1926abee8ab1f 148388 python optional python-keystonemiddleware_10.9.0.orig.tar.xz c7f6af336e84d43d7850940534a1bbdb 7308 python optional python-keystonemiddleware_10.9.0-2+deb13u1.debian.tar.xz 86d61d85eaa824b0a9ef587bc95eeba4 19290 python optional python-keystonemiddleware_10.9.0-2+deb13u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmlt64cACgkQ1BatFaxr Q/4wNA/+OA5tNwsglHcCV60S4o6v5EJo6Z+G02bZM5N28W9VkVC7AuaShDj4IOTB DP6pGDg/AvRfckcgkympiijqMyX4VQrruxxeD9IXoa2UR7f/ILWrk/i5XbHKhd2W 1GDwgov/gKhhoRq4bh7jn6eIaHESExSOJgJy49G17rx5WpJKeSEDafxsPYt197fH emsMteTx76Z1BgBrX1JMLaQQS24nJl4PilnABp7OVNw1YxzfNTULYYzKMUAd4aue XJ8SsUGqHb6y8eJounKPIWAnLYkRzkXd4P6W3+GQDmhACVsvvpAx2D00GduIlCxe x2bc5JaItKq2zsUFHuXs25q+drGGavbi5IYaduDWEdknEnPObYB3ecqxamWcNTCa DZsNtlLgFFgSm2dZLKeByhZcE/GxPpRJXKfQtDOL/nLPaF6YmWqEj7sld+tmI1zA qNNWmiV2rdmJL8qLhaY9/AxiLu/eECqT0pRzAv0zfqztTZ/2JzEV18upvXhJIGAG 8pV06G6mTYSYlwHUgTzVpooflpq6xQ7TWM0GHieUAhBWTInC936JJ7vaZr1Nh6jm ADfgEN442YKIKrhT7q6XZSPzpAuJhpTa07IX9zpgXH7h6P/65zjzc5s3ksUp9P3O 3GWyUedyK2nEGW2Zhy/AASBbzHmONQPbJbN7keP4BDupcs6U0Cs= =94wD -----END PGP SIGNATURE-----