CVE-2026-50589
published 2026-06-05CVE-2026-50589: In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.43%
35.1th percentile
In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openstack | ironic | >= 32.0.0 < 37.0.0 | 37.0.0 |
| openstack | ironic | >= 32.0.0 < 37.0.0 | 37.0.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
ghsa·2026-06-05
CVE-2026-50589 [MEDIUM] CWE-502 OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
In OpenStack Ironic 32.0.0 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.
GHSA
In OpenStack Ironic 32 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.
ghsa_unreviewed·2026-06-05
CVE-2026-50589 [MEDIUM] CWE-770 In OpenStack Ironic 32 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.
In OpenStack Ironic 32 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.
Red Hat
openstack-ironic: OpenStack Ironic: Denial of Service via crafted JSON string
vendor_redhat·2026-06-04·CVSS 7.5
CVE-2026-50589 [HIGH] CWE-502 openstack-ironic: OpenStack Ironic: Denial of Service via crafted JSON string
openstack-ironic: OpenStack Ironic: Denial of Service via crafted JSON string
In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.
A flaw was found in OpenStack Ironic. An unauthenticated malicious user could exploit this vulnerability by submitting a specially crafted JSON (JavaScript Object Notation) string to certain API (Application Programming Interface) or JSON-RPC (Remote Procedure Call) service endpoints. This could lead to a service crash, resulting in a Denial of Service (DoS) for affected systems.
Mitigation: To reduce the risk of exploitation, restrict network access to the OpenStack Ironic API and JSON-RPC service endpoints. Configure firewall r
No detection rules found.
No public exploits indexed.
https://bugs.launchpad.net/ironic/+bug/2154288https://wiki.openstack.org/wiki/OSSN/OSSN-0099http://www.openwall.com/lists/oss-security/2026/06/06/2https://access.redhat.com/security/cve/CVE-2026-50589https://bugs.launchpad.net/ironic/+bug/2154288https://bugzilla.redhat.com/show_bug.cgi?id=2485353https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50589.json
2026-06-05
Published