<?xml version="1.0"?>
<oembed><version>1.0</version><provider_name>Yaook</provider_name><provider_url>https://yaook.cloud/en</provider_url><author_name>Stefan Hoffmann</author_name><author_url>https://yaook.cloud/en/author/yaook-admin/</author_url><title>security-advisories/ossa-2026-037 &#xBB; Yaook</title><type>rich</type><width>600</width><height>338</height><html>&lt;blockquote class="wp-embedded-content" data-secret="XwFtwhypOV"&gt;&lt;a href="https://yaook.cloud/en/security-advisories-ossa-2026-037/"&gt;security-advisories/ossa-2026-037&lt;/a&gt;&lt;/blockquote&gt;&lt;iframe sandbox="allow-scripts" security="restricted" src="https://yaook.cloud/en/security-advisories-ossa-2026-037/embed/#?secret=XwFtwhypOV" width="600" height="338" title="&#x201C;security-advisories/ossa-2026-037&#x201D; &#x2014; Yaook" data-secret="XwFtwhypOV" frameborder="0" marginwidth="0" marginheight="0" scrolling="no" class="wp-embedded-content"&gt;&lt;/iframe&gt;&lt;script&gt;
/*! This file is auto-generated */
!function(d,l){"use strict";l.querySelector&amp;&amp;d.addEventListener&amp;&amp;"undefined"!=typeof URL&amp;&amp;(d.wp=d.wp||{},d.wp.receiveEmbedMessage||(d.wp.receiveEmbedMessage=function(e){var t=e.data;if((t||t.secret||t.message||t.value)&amp;&amp;!/[^a-zA-Z0-9]/.test(t.secret)){for(var s,r,n,a=l.querySelectorAll('iframe[data-secret="'+t.secret+'"]'),o=l.querySelectorAll('blockquote[data-secret="'+t.secret+'"]'),c=new RegExp("^https?:$","i"),i=0;i&lt;o.length;i++)o[i].style.display="none";for(i=0;i&lt;a.length;i++)s=a[i],e.source===s.contentWindow&amp;&amp;(s.removeAttribute("style"),"height"===t.message?(1e3&lt;(r=parseInt(t.value,10))?r=1e3:~~r&lt;200&amp;&amp;(r=200),s.height=r):"link"===t.message&amp;&amp;(r=new URL(s.getAttribute("src")),n=new URL(t.value),c.test(n.protocol))&amp;&amp;n.host===r.host&amp;&amp;l.activeElement===s&amp;&amp;(d.top.location.href=t.value))}},d.addEventListener("message",d.wp.receiveEmbedMessage,!1),l.addEventListener("DOMContentLoaded",function(){for(var e,t,s=l.querySelectorAll("iframe.wp-embedded-content"),r=0;r&lt;s.length;r++)(t=(e=s[r]).getAttribute("data-secret"))||(t=Math.random().toString(36).substring(2,12),e.src+="#?secret="+t,e.setAttribute("data-secret",t)),e.contentWindow.postMessage({message:"ready",secret:t},"*")},!1)))}(window,document);
//# sourceURL=https://yaook.cloud/wp-includes/js/wp-embed.min.js
&lt;/script&gt;</html><description>YAOOK Security Advisory for keystone cve-2026-pending OSSA-2026-037 Date: 2026-08-25 Upstream advisory: https://security.openstack.org/ossa/OSSA-2026-037.html Upstream bug: https://bugs.launchpad.net/keystone/+bug/2153453 https://bugs.launchpad.net/keystone/+bug/2158538 What are OSSA-2026-037 and how do they affect YAOOK? Grzegorz Grasza (Red Hat) and Tim Shephard (roiai.ca) independently identified that OpenStack Keystone does not consistently enforce scope restrictions on tokens obtained via delegated authentication methods (ec2credential, application credential, OAuth1 [&hellip;]</description></oembed>
