OpenStack / Ironic
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-90461 | ironic: OpenStack Ironic: Information disclosure via unexpected credential transmission | MEDIUM | 6.3 | Sep 11, 2026 |
| CVE-2026-74250 | ironic: OpenStack Ironic: Autodetect deploy interface fails to run cleaning | MEDIUM | 6.3 | Aug 14, 2026 |
| CVE-2026-71201 | ironic: OpenStack Ironic: Information disclosure via crafted request | MEDIUM | 5.0 | Aug 5, 2026 |
| CVE-2026-54423 | openstack-ironic: openstack-ironic: Arbitrary IPMI command execution via send_raw deployment step | HIGH | 8.2 | Jul 10, 2026 |
| CVE-2026-44918 | openstack-ironic: Prevent rehoming resources to nodes with different owner | HIGH | 8.7 | Jul 10, 2026 |
| CVE-2026-54421 | openstack ironic: OpenStack Ironic: Information disclosure via PATCH request on volume properties | MEDIUM | 6.8 | Jun 14, 2026 |
| CVE-2026-50589 | openstack-ironic: OpenStack Ironic: Denial of Service via crafted JSON string | HIGH | 7.5 | Jun 4, 2026 |
| CVE-2026-48681 | openstack-ironic: OpenStack Ironic: File overwrite via directory traversal vulnerability | HIGH | 8.1 | Jun 4, 2026 |
| CVE-2026-44917 | OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template. | MEDIUM | 4.9 | Jun 4, 2026 |
| CVE-2026-46447 | OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info. | HIGH | 7.7 | Jun 3, 2026 |
| CVE-2026-44919 | In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. | MEDIUM | 6.5 | May 14, 2026 |
| CVE-2026-44916 | In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing. | LOW | 3.0 | May 8, 2026 |
| CVE-2026-42997 | OpenStack Ironic: OpenStack Ironic: Information disclosure via credential forwarding during mold import | HIGH | 7.7 | May 5, 2026 |
| CVE-2026-42510 | OpenStack Ironic: ipmitool: OpenStack Ironic: Arbitrary Code Execution via Remote Hardware Management | HIGH | 7.2 | Apr 28, 2026 |
| CVE-2025-44021 | openstack-ironic: unsafe image file:// paths | MEDIUM | 5.4 | May 8, 2025 |
| CVE-2015-7514 | openstack-ironic: Ironic does not honor clean steps | MEDIUM | 6.5 | Jun 7, 2017 |
Showing 1 to 14 of 14 CVEs