
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69233 is a denial-of-service vulnerability in Apache CloudStack caused by multiple time-of-check time-of-use (TOCTOU) race conditions in the resource count check and increment logic, combined with missing input validations. It allows authenticated users to exceed configured allocation limits for their accounts or domains, degrading shared infrastructure resources. Affected versions include Apache CloudStack 4.0.0 through 4.20.2.0 and 4.21.0.0 through 4.22.0.0. The vulnerability was disclosed on May 8, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) per NVD, though ENISA's EUVD rates it 6.5 (Medium) (Apache Advisory, oss-security).
The root cause is classified under CWE-367 (Time-of-Check Time-of-Use Race Condition) and CWE-770 (Allocation of Resources Without Limits or Throttling). The flaw exists in CloudStack's resource count check and increment logic, where concurrent requests can race past quota enforcement checks before the resource counter is updated, allowing a user to allocate more resources than their configured limit permits. An attacker with low-privileged network access can exploit this by sending multiple simultaneous resource allocation requests, exploiting the window between the quota check and the counter increment. No special user interaction is required, but the attack complexity is rated High due to the timing requirements of the race condition (Apache Advisory, oss-security).
Successful exploitation allows an authenticated attacker to exceed their assigned resource allocation limits (e.g., VMs, storage, network resources) within Apache CloudStack, exhausting shared infrastructure capacity and causing denial of service conditions for other tenants or the platform as a whole. The impact is limited to availability — there is no confidentiality or integrity impact. In multi-tenant cloud environments, this could disrupt services for all users sharing the affected infrastructure (Apache Advisory, oss-security).
deployVirtualMachine, createVolume) from the same user in very short time windows.Apache has released patched versions: 4.20.3.0 and 4.22.0.1, which fix the race conditions and missing validations in the resource allocation logic. All users running affected versions (4.0.0–4.20.2.0 or 4.21.0.0–4.22.0.0) should upgrade immediately. As an interim workaround, administrators can implement strict rate limiting on the CloudStack API and enforce resource allocation controls at the infrastructure level (e.g., hypervisor or storage layer) to reduce the risk of quota bypass (Apache Advisory, oss-security).
ShapeBlue, a major Apache CloudStack contributor and managed service provider, published a security advisory covering the 4.20.3.0 and 4.22.0.1 releases that address this and related issues (ShapeBlue). The vulnerability was also discussed on the oss-security mailing list and noted on Bluesky by the infosec community shortly after disclosure. Overall community reaction has been measured, consistent with the moderate severity rating and absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."