Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Mistral could be made to expose sensitive information or run code.. ========================================================================== Ubuntu Security Notice USN-8422-1 June 11, 2026 mistral vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Mistral could be made to expose sensitive information or run code. Software Description: - mistral: OpenStack Workflow Service Details: Eduardo Gonzalez Gutierrez and Arnaud Morin discovered that Mistral did not properly enforce access policies on some API endpoints. An attacker could possibly execute arbitrary code on a Mistral worker and possibly extract sensitive data including service credentials from it. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS mistral-api 22.0.0-0ubuntu1.1 mistral-common 22.0.0-0ubuntu1.1 mistral-engine 22.0.0-0ubuntu1.1 mistral-event-engine 22.0.0-0ubuntu1.1 mistral-executor 22.0.0-0ubuntu1.1 python3-mistral 22.0.0-0ubuntu1.1 Ubuntu 25.10 mistral-api 21.0.0-0ubuntu1.1 mistral-common 21.0.0-0ubuntu1.1 mistral-engine 21.0.0-0ubuntu1.1 mistral-event-engine 21.0.0-0ubuntu1.1 mistral-executor 21.0.0-0ubuntu1.1 python3-mistral 21.0.0-0ubuntu1.1 Ubuntu 24.04 LTS mistral-api 18.0.1-0ubuntu1.1 mistral-common 18.0.1-0ubuntu1.1 mistral-engine 18.0.1-0ubuntu1.1 mistral-event-engine 18.0.1-0ubuntu1.1 mistral-executor 18.0.1-0ubuntu1.1 python3-mistral 18.0.1-0ubuntu1.1 Ubuntu 22.04 LTS mistral-api 14.0.0-0ubuntu1.1 mistral-common 14.0.0-0ubuntu1.1 mistral-engine 14.0.0-0ubuntu1.1 mistral-event-engine 14.0.0-0ubuntu1.1 mistral-executor 14.0.0-0ubuntu1.1 python3-mistral 14.0.0-0ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8422-1 CVE-2026-41283 Package Information: https://launchpad.net/ubuntu/+source/mistral/22.0.0-0ubuntu1.1 https://launchpad.net/ubuntu/+source/mistral/21.0.0-0ubuntu1.1 https://launchpad.net/ubuntu/+source/mistral/18.0.1-0ubuntu1.1 https://launchpad.net/ubuntu/+source/mistral/14.0.0-0ubuntu1.1 . Mistral in Ubuntu exposes sensitive information and allows code execution risks. Ensure proper update for protection.. Mistral Update, Ubuntu Vulnerabilities, OpenStack Security. . Severity: Important. LinuxSecurity.com Team
Eduardo Gonzalez Gutierrez and Arnaud Morin discovered that multiple API endpoints of Mistral, the OpenStack Workflow, improperly enforced access policies, which could result in information disclosure. For the oldstable distribution (bookworm), this problem has been fixed in version 15.0.0-1+deb12u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6333-1
Several security issues were fixed in Mistral.. ========================================================================== Ubuntu Security Notice USN-7465-1 April 28, 2025 mistral, python-mistral-lib vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Mistral. Software Description: - mistral: OpenStack Workflow service - API - python-mistral-lib: Mistral shared routines and utilities Details: It was discovered that Mistral incorrectly handled nested anchors in YAML files. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-16848) Pierre Gaxatte discovered that Mistral incorrectly handled erroneous SSH private key filename commands. An attacker could possibly use this issue to expose sensitive information. (CVE-2018-16849) It was discovered that Mistral incorrectly handled the permissions of sensitive log files. An attacker could possibly use this issue to expose sensitive information. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-3866) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS mistral-api 6.0.0-0ubuntu1.1+esm1 Available with Ubuntu Pro python-mistral 6.0.0-0ubuntu1.1+esm1 Available with Ubuntu Pro python-mistral-lib 0.4.0-0ubuntu1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS mistral-api 2.0.0-1ubuntu2+esm1 Available with Ubuntu Pro python-mistral 2.0.0-1ubuntu2+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7465-1 CVE-2018-16848, CVE-2018-16849, CVE-2019-3866 . Uncover essential updates for Mistral within Ubuntu LTS versions, targeting vulnerabilities that risk user information leakage and operational interruptions.. Ubuntu Security, Mistral Software, Python Issues, Workflow Vulnerabilities, Linux Administration. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.