CVE-2026-44916
published 2026-05-08CVE-2026-44916: In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.
PriorityP411low3CVSS 3.1
AVNACHPRHUINSCCLINAN
EPSS
0.34%
25.7th percentile
In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openstack | ironic | >= 17.0.0 < 26.1.7 | 26.1.7 |
| openstack | ironic | >= 27.0.0 < 29.0.6 | 29.0.6 |
| openstack | ironic | >= 30.0.0 < 32.0.2 | 32.0.2 |
| openstack | ironic | >= 33.0.0 < 35.0.2 | 35.0.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenStack Ironic up to 35.0.1 instance_info['ks_template'] special elements used in a template engine (Nessus ID 313241)
vuldb·2026-05-09·CVSS 3.0
CVE-2026-44916 [LOW] OpenStack Ironic up to 35.0.1 instance_info['ks_template'] special elements used in a template engine (Nessus ID 313241)
A vulnerability has been found in OpenStack Ironic up to 35.0.1 and classified as problematic. Affected by this vulnerability is an unknown functionality. Performing a manipulation of the argument instance_info['ks_template'] results in improper neutralization of special elements used in a template engine.
This vulnerability was named CVE-2026-44916. The attack may be initiated remotely. There is no available exploit.
GHSA
GHSA-979m-gf7m-rg53: In OpenStack Ironic through 35
ghsa_unreviewed·2026-05-08
CVE-2026-44916 [LOW] CWE-1336 GHSA-979m-gf7m-rg53: In OpenStack Ironic through 35
In OpenStack Ironic through 35.x, instance_info['ks_template'] is rendered without sandboxing.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-08
Published