A vulnerability, which was classified as critical, was found in OpenStack Swift up to 2.35.3/2.36.2/2.37.2/2.38.0. Affected by this issue is some unknown functionality of the component S3API Middleware. Such manipulation of the argument X-Amz-Copy-Source leads to improper authorization.
This vulnerability is traded as CVE-2026-71191. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.