ironic
OpenStack Bare Metal Provisioning
Activity
- Latest release
- 1w ago
- Total releases
- 119
- Cadence
- ~9 days
- Last 12 months
- 17
Details
- License
- Apache-2.0
- First release
- Dec 19, 2018
| Version | Released | |
|---|---|---|
32.1.0
minor
3 CVEs
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-50589
GHSA-q3g8-rjrx-59ph
PYSEC-2026-216
Jun 05, 2026
OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
In OpenStack Ironic 32.0.0 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash. Affected versions
32.0.0
32.0.1
32.1.0
33.0.0
34.0.0
35.0.0
35.0.1
35.1.0
36.0.0
Fixed in
37.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
32.1.0
minor
Dependencies (61)
+ 53 more |
|
29.1.0
minor
2 CVEs
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev |
29.1.0
minor
Dependencies (61)
+ 53 more |
|
35.1.0
minor
2 CVEs
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-50589
GHSA-q3g8-rjrx-59ph
PYSEC-2026-216
Jun 05, 2026
OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
In OpenStack Ironic 32.0.0 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash. Affected versions
32.0.0
32.0.1
32.1.0
33.0.0
34.0.0
35.0.0
35.0.1
35.1.0
36.0.0
Fixed in
37.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
35.1.0
minor
Dependencies (50)
+ 42 more |
|
38.0.0
major
|
38.0.0
major
Dependencies (52)
+ 44 more |
|
29.0.6
patch
2 CVEs
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev |
29.0.6
patch
Dependencies (61)
+ 53 more |
|
37.0.0
major
1 CVE
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
37.0.0
major
Dependencies (50)
+ 42 more |
|
35.0.1
patch
5 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-50589
GHSA-q3g8-rjrx-59ph
PYSEC-2026-216
Jun 05, 2026
OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
In OpenStack Ironic 32.0.0 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash. Affected versions
32.0.0
32.0.1
32.1.0
33.0.0
34.0.0
35.0.0
35.0.1
35.1.0
36.0.0
Fixed in
37.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
35.0.1
patch
Dependencies (50)
+ 42 more |
|
29.0.5
patch
5 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev |
29.0.5
patch
Dependencies (61)
+ 53 more |
|
32.0.1
patch
6 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-50589
GHSA-q3g8-rjrx-59ph
PYSEC-2026-216
Jun 05, 2026
OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
In OpenStack Ironic 32.0.0 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash. Affected versions
32.0.0
32.0.1
32.1.0
33.0.0
34.0.0
35.0.0
35.0.1
35.1.0
36.0.0
Fixed in
37.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
32.0.1
patch
Dependencies (61)
+ 53 more |
|
36.0.0
major
3 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-50589
GHSA-q3g8-rjrx-59ph
PYSEC-2026-216
Jun 05, 2026
OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
In OpenStack Ironic 32.0.0 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash. Affected versions
32.0.0
32.0.1
32.1.0
33.0.0
34.0.0
35.0.0
35.0.1
35.1.0
36.0.0
Fixed in
37.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
36.0.0
major
Dependencies (50)
+ 42 more |
|
26.1.6
patch
5 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev |
26.1.6
patch
Dependencies (59)
+ 51 more |
|
35.0.0
major
6 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-50589
GHSA-q3g8-rjrx-59ph
PYSEC-2026-216
Jun 05, 2026
OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
In OpenStack Ironic 32.0.0 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash. Affected versions
32.0.0
32.0.1
32.1.0
33.0.0
34.0.0
35.0.0
35.0.1
35.1.0
36.0.0
Fixed in
37.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
35.0.0
major
Dependencies (50)
+ 42 more |
|
26.1.5
patch
5 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev |
26.1.5
patch
Dependencies (59)
+ 51 more |
|
34.0.0
major
6 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-50589
GHSA-q3g8-rjrx-59ph
PYSEC-2026-216
Jun 05, 2026
OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
In OpenStack Ironic 32.0.0 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash. Affected versions
32.0.0
32.0.1
32.1.0
33.0.0
34.0.0
35.0.0
35.0.1
35.1.0
36.0.0
Fixed in
37.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
34.0.0
major
Dependencies (50)
+ 42 more |
|
33.0.0
major
6 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-50589
GHSA-q3g8-rjrx-59ph
PYSEC-2026-216
Jun 05, 2026
OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
In OpenStack Ironic 32.0.0 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash. Affected versions
32.0.0
32.0.1
32.1.0
33.0.0
34.0.0
35.0.0
35.0.1
35.1.0
36.0.0
Fixed in
37.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
33.0.0
major
Dependencies (50)
+ 42 more |
|
26.1.4
patch
5 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev |
26.1.4
patch
Dependencies (59)
+ 51 more |
|
29.0.4
patch
5 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev |
29.0.4
patch
Dependencies (61)
+ 53 more |
|
32.0.0
major
6 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-50589
GHSA-q3g8-rjrx-59ph
PYSEC-2026-216
Jun 05, 2026
OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
In OpenStack Ironic 32.0.0 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash. Affected versions
32.0.0
32.0.1
32.1.0
33.0.0
34.0.0
35.0.0
35.0.1
35.1.0
36.0.0
Fixed in
37.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
32.0.0
major
Dependencies (61)
+ 53 more |
|
31.0.0
major
5 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev |
31.0.0
major
Dependencies (62)
+ 54 more |
|
29.0.3
patch
5 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev |
29.0.3
patch
Dependencies (61)
+ 53 more |
|
24.1.5
patch
5 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev |
24.1.5
patch
Dependencies (60)
+ 52 more |
|
26.1.3
patch
5 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev |
26.1.3
patch
Dependencies (59)
+ 51 more |
|
30.0.0
major
5 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev |
30.0.0
major
Dependencies (61)
+ 53 more |
|
26.1.2
patch
5 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev |
26.1.2
patch
Dependencies (59)
+ 51 more |
|
24.1.4
patch
5 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev |
24.1.4
patch
Dependencies (60)
+ 52 more |
|
29.0.2
patch
5 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev |
29.0.2
patch
Dependencies (61)
+ 53 more |
|
29.0.1
patch
5 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev |
29.0.1
patch
Dependencies (61)
+ 53 more |
|
23.0.5
patch
6 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
23.0.5
patch
Dependencies (60)
+ 52 more |
|
29.0.0
major
6 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
29.0.0
major
Dependencies (61)
+ 53 more |
|
23.0.4
patch
6 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
23.0.4
patch
Dependencies (60)
+ 52 more |
|
28.0.0
major
6 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
28.0.0
major
Dependencies (60)
+ 52 more |
|
27.0.0
major
6 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
27.0.0
major
Dependencies (58)
+ 50 more |
|
21.4.4
patch
7 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2024-47211
PYSEC-2026-1468
GHSA-8h22-6qwx-q4w9
Jul 07, 2026
OpenStack Ironic fails to verify checksums of supplied image_source URLs
Medium
Network
Low
None
None
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 73 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
25.0.0
26.0.0
26.1.0
9.1.6
9.1.7
Fixed in
23.0.3
24.1.3
26.1.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
21.4.4
patch
Dependencies (58)
+ 50 more |
|
26.1.1
patch
5 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev |
26.1.1
patch
Dependencies (59)
+ 51 more |
|
23.0.3
patch
6 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
23.0.3
patch
Dependencies (60)
+ 52 more |
|
24.1.3
patch
5 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev |
24.1.3
patch
Dependencies (60)
+ 52 more |
|
26.1.0
minor
7 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2024-47211
PYSEC-2026-1468
GHSA-8h22-6qwx-q4w9
Jul 07, 2026
OpenStack Ironic fails to verify checksums of supplied image_source URLs
Medium
Network
Low
None
None
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 73 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
25.0.0
26.0.0
26.1.0
9.1.6
9.1.7
Fixed in
23.0.3
24.1.3
26.1.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
26.1.0
minor
Dependencies (59)
+ 51 more |
|
21.4.3
patch
7 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2024-47211
PYSEC-2026-1468
GHSA-8h22-6qwx-q4w9
Jul 07, 2026
OpenStack Ironic fails to verify checksums of supplied image_source URLs
Medium
Network
Low
None
None
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 73 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
25.0.0
26.0.0
26.1.0
9.1.6
9.1.7
Fixed in
23.0.3
24.1.3
26.1.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
21.4.3
patch
Dependencies (58)
+ 50 more |
|
23.0.2
patch
7 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2024-47211
PYSEC-2026-1468
GHSA-8h22-6qwx-q4w9
Jul 07, 2026
OpenStack Ironic fails to verify checksums of supplied image_source URLs
Medium
Network
Low
None
None
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 73 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
25.0.0
26.0.0
26.1.0
9.1.6
9.1.7
Fixed in
23.0.3
24.1.3
26.1.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
23.0.2
patch
Dependencies (60)
+ 52 more |
|
24.1.2
patch
7 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2024-47211
PYSEC-2026-1468
GHSA-8h22-6qwx-q4w9
Jul 07, 2026
OpenStack Ironic fails to verify checksums of supplied image_source URLs
Medium
Network
Low
None
None
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 73 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
25.0.0
26.0.0
26.1.0
9.1.6
9.1.7
Fixed in
23.0.3
24.1.3
26.1.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
24.1.2
patch
Dependencies (60)
+ 52 more |
|
21.4.2
patch
7 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2024-47211
PYSEC-2026-1468
GHSA-8h22-6qwx-q4w9
Jul 07, 2026
OpenStack Ironic fails to verify checksums of supplied image_source URLs
Medium
Network
Low
None
None
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 73 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
25.0.0
26.0.0
26.1.0
9.1.6
9.1.7
Fixed in
23.0.3
24.1.3
26.1.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
21.4.2
patch
Dependencies (58)
+ 50 more |
|
26.0.0
major
7 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2024-47211
PYSEC-2026-1468
GHSA-8h22-6qwx-q4w9
Jul 07, 2026
OpenStack Ironic fails to verify checksums of supplied image_source URLs
Medium
Network
Low
None
None
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 73 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
25.0.0
26.0.0
26.1.0
9.1.6
9.1.7
Fixed in
23.0.3
24.1.3
26.1.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
26.0.0
major
Dependencies (59)
+ 51 more |
|
25.0.0
major
7 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2024-47211
PYSEC-2026-1468
GHSA-8h22-6qwx-q4w9
Jul 07, 2026
OpenStack Ironic fails to verify checksums of supplied image_source URLs
Medium
Network
Low
None
None
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 73 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
25.0.0
26.0.0
26.1.0
9.1.6
9.1.7
Fixed in
23.0.3
24.1.3
26.1.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
25.0.0
major
Dependencies (59)
+ 51 more |
|
23.0.1
patch
7 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2024-47211
PYSEC-2026-1468
GHSA-8h22-6qwx-q4w9
Jul 07, 2026
OpenStack Ironic fails to verify checksums of supplied image_source URLs
Medium
Network
Low
None
None
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 73 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
25.0.0
26.0.0
26.1.0
9.1.6
9.1.7
Fixed in
23.0.3
24.1.3
26.1.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
23.0.1
patch
Dependencies (60)
+ 52 more |
|
21.4.1
patch
7 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2024-47211
PYSEC-2026-1468
GHSA-8h22-6qwx-q4w9
Jul 07, 2026
OpenStack Ironic fails to verify checksums of supplied image_source URLs
Medium
Network
Low
None
None
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 73 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
25.0.0
26.0.0
26.1.0
9.1.6
9.1.7
Fixed in
23.0.3
24.1.3
26.1.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
21.4.1
patch
Dependencies (58)
+ 50 more |
|
21.1.2
patch
7 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2024-47211
PYSEC-2026-1468
GHSA-8h22-6qwx-q4w9
Jul 07, 2026
OpenStack Ironic fails to verify checksums of supplied image_source URLs
Medium
Network
Low
None
None
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 73 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
25.0.0
26.0.0
26.1.0
9.1.6
9.1.7
Fixed in
23.0.3
24.1.3
26.1.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
21.1.2
patch
Dependencies (58)
+ 50 more |
|
24.1.1
patch
7 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2024-47211
PYSEC-2026-1468
GHSA-8h22-6qwx-q4w9
Jul 07, 2026
OpenStack Ironic fails to verify checksums of supplied image_source URLs
Medium
Network
Low
None
None
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 73 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
25.0.0
26.0.0
26.1.0
9.1.6
9.1.7
Fixed in
23.0.3
24.1.3
26.1.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
24.1.1
patch
Dependencies (60)
+ 52 more |
|
24.1.0
minor
7 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2024-47211
PYSEC-2026-1468
GHSA-8h22-6qwx-q4w9
Jul 07, 2026
OpenStack Ironic fails to verify checksums of supplied image_source URLs
Medium
Network
Low
None
None
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 73 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
25.0.0
26.0.0
26.1.0
9.1.6
9.1.7
Fixed in
23.0.3
24.1.3
26.1.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
24.1.0
minor
Dependencies (60)
+ 52 more |
|
21.1.1
patch
7 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2024-47211
PYSEC-2026-1468
GHSA-8h22-6qwx-q4w9
Jul 07, 2026
OpenStack Ironic fails to verify checksums of supplied image_source URLs
Medium
Network
Low
None
None
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 73 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
25.0.0
26.0.0
26.1.0
9.1.6
9.1.7
Fixed in
23.0.3
24.1.3
26.1.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
21.1.1
patch
Dependencies (58)
+ 50 more |
|
20.1.3
patch
7 CVEs
CVE-2026-54421
PYSEC-2026-3852
GHSA-j4cw-mcg2-2q78
Sep 10, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 61 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
37.0.0
Fixed in
29.0.6
32.0.2
35.0.2
37.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48681
PYSEC-2026-3470
GHSA-9v62-qx4c-44x5
Jul 23, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-46447
PYSEC-2026-3471
GHSA-jrh2-f5jc-xpgr
Jul 23, 2026
OpenStack Ironic allows Boot Script Injection
5.8
/ 10
Medium
Network
High
High
None
Changed
None
High
None
OpenStack Ironic through 35.0.x allows Boot Script Injection. Affected versions
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
+ 59 more Show less
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
Fixed in
26.1.7
29.0.6
32.0.2
35.0.2
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-44919
PYSEC-2026-2524
GHSA-4g73-w726-53h3
Jul 13, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 103 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
35.0.1
36.0.0
9.1.6
9.1.7
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-42510
PYSEC-2026-2525
GHSA-wqpv-c3pp-3m58
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 101 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.0.0
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.0.0
28.0.0
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
29.0.6
30.0.0
31.0.0
32.0.0
32.0.1
33.0.0
34.0.0
35.0.0
9.1.6
9.1.7
Fixed in
35.0.1
References Updated Jul 20, 2026 · Source: OSV.dev
CVE-2024-47211
PYSEC-2026-1468
GHSA-8h22-6qwx-q4w9
Jul 07, 2026
OpenStack Ironic fails to verify checksums of supplied image_source URLs
Medium
Network
Low
None
None
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 73 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
25.0.0
26.0.0
26.1.0
9.1.6
9.1.7
Fixed in
23.0.3
24.1.3
26.1.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-44021
GHSA-q3m2-crgq-5p3q
PYSEC-2025-38
May 08, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
2.8
/ 10
Low
Local
High
Low
None
Changed
None
Low
None
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1. Affected versions
0.0
10.1.10
10.1.7
10.1.8
10.1.9
11.1.1
11.1.2
11.1.3
11.1.4
12.0.0
12.1.0
12.1.1
+ 79 more Show less
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.0.0
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.0.0
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.0.0
22.1.0
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.0.0
24.1.0
24.1.1
24.1.2
9.1.6
9.1.7
25.0.0
26.0.0
26.1.0
27.0.0
28.0.0
29.0.0
Fixed in
24.1.3
26.1.1
29.0.1
References
Updated Jun 09, 2026 · Source: OSV.dev |
20.1.3
patch
Dependencies (58)
+ 50 more |