Known Vulnerabilities for Ironic by Openstack
Listed below are 9 of the newest known vulnerabilities associated with "Ironic" by "Openstack".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-74250 json | In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with... | Not Provided | 2026-08-14 | 2026-08-17 |
| CVE-2026-71201 json | In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-66138 json | In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code exec... | Not Provided | 2026-07-24 | 2026-07-24 |
| CVE-2026-54423 json | In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can ma... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-54422 json | In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may b... | Not Provided | 2026-07-24 | 2026-07-24 |
| CVE-2026-54421 json | In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ir... | Not Provided | 2026-06-14 | 2026-06-16 |
| CVE-2026-50589 json | In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints ... | Not Provided | 2026-06-05 | 2026-07-16 |
| CVE-2026-48681 json | OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO ima... | Not Provided | 2026-06-04 | 2026-06-04 |
| CVE-2026-46447 json | OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or nod... | Not Provided | 2026-06-03 | 2026-06-15 |
| CVE-2026-44919 json | Not Provided | 2026-05-14 | 2026-06-17 |