Openstack Ironic vulnerabilities
17 known vulnerabilities affecting openstack/ironic.
Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6MEDIUM8LOW2UNKNOWN1
Vulnerabilities
Page 1 of 1
CVE-2026-48681P3HIGHCVSS 8.1≥ 17.0.0, < 26.1.7≥ 27.0.0, < 29.0.6+2 more2026-06-04
CVE-2026-48681 [HIGH] CWE-23 CVE-2026-48681: OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployme
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
ghsanvd
CVE-2026-42997P3HIGHCVSS 7.7≥ 17.0.0, < 26.1.6≥ 27.0.0, < 29.0.5+2 more2026-05-05
CVE-2026-42997 [HIGH] CWE-669 CVE-2026-42997: An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking m
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The
nvd
CVE-2026-54423P3HIGHCVSS 8.2≥ 22.1.0, < 29.0.6≥ 30.0.0, < 32.0.2+2 more2026-07-10
CVE-2026-54423 [HIGH] CWE-424 CVE-2026-54423: In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI ma
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.
nvd
CVE-2026-46447P3HIGHCVSS 7.7≥ 17.0.0, < 26.1.7≥ 27.0.0, < 29.0.6+2 more2026-06-03
CVE-2026-46447 [HIGH] CWE-669 CVE-2026-46447: OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can se
OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.
ghsanvd
CVE-2016-4985P3HIGHCVSS 7.5≥ 0, < 4.2.5≥ 5.0, < 5.1.22022-05-13
CVE-2016-4985 [HIGH] CWE-200 OpenStack Ironic Exposure of Sensitive Information to an Unauthorized Actor
OpenStack Ironic Exposure of Sensitive Information to an Unauthorized Actor
The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the `v1/drivers/$DRI
ghsaosv
CVE-2026-50589P3HIGHCVSS 7.5≥ 32.0.0, < 37.0.02026-06-05
CVE-2026-50589 [HIGH] CWE-770 CVE-2026-50589: In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON
In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.
ghsanvd
CVE-2026-42510P3MEDIUMCVSS 6.6≥ 4.3.0, ≤ 26.1.6≥ 27.0.0, ≤ 29.0.5+2 more2026-04-28
CVE-2026-42510 [MEDIUM] CWE-829 CVE-2026-42510: OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a c
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
ghsanvd
CVE-2023-2088P3UNKNOWN≥ 0, < 1:20.1.0-0ubuntu1.12023-07-24
cinder, ironic, nova, python-glance-store, python-os-brick vulnerability
cinder, ironic, nova, python-glance-store, python-os-brick vulnerability
Jan Wasilewski and Gorka Eguileor discovered that OpenStack incorrectly
handled deleted volume attachments. An authenticated user or attacker could
possibly use this issue to gain access to sensitive information.
This update may require configuration changes, please see the upstream
advisory and the other links below for more information:
https://se
osv
CVE-2026-54421P4MEDIUMCVSS 6.8≥ 17.0.0, < 29.0.6≥ 30.0.0, < 32.0.2+2 more2026-06-14
CVE-2026-54421 [MEDIUM] CWE-212 CVE-2026-54421: In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the u
In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.
nvd
CVE-2015-7514P4MEDIUMCVSS 6.5v4.2.0v4.2.12017-06-07
CVE-2015-7514 [MEDIUM] CWE-200 CVE-2015-7514: OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authen
OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.
nvdosv
CVE-2026-44918P4MEDIUMCVSS 5.5≥ 27.0.0, < 29.0.6≥ 30.0.0, < 32.0.2+2 more2026-07-10
CVE-2026-44918 [MEDIUM] CWE-862 CVE-2026-44918: OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project withou
OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
nvd
CVE-2026-44917P4MEDIUMCVSS 4.9≥ 17.0.0, < 26.1.7≥ 27.0.0, < 29.0.6+2 more2026-06-04
CVE-2026-44917 [MEDIUM] CWE-669 CVE-2026-44917: OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read loc
OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
nvd
CVE-2024-47211P4MEDIUMCVSS 5.3≥ 25.0.0, < 26.1.1≥ 23.1.0, < 24.1.3+2 more2024-10-04
CVE-2024-47211 [MEDIUM] CWE-354 OpenStack Ironic fails to verify checksums of supplied image_source URLs
OpenStack Ironic fails to verify checksums of supplied image_source URLs
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.
ghsaosv
CVE-2024-44082P4MEDIUMCVSS 4.3≥ 0, < 1:26.1.0-12024-09-06
CVE-2024-44082 [MEDIUM] CVE-2024-44082: In OpenStack Ironic before 26
In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, in which a crafted image could be used by an authenticated user to exploit undesired behaviors in qemu-img, including possible unauthorized access to potentially sensitive data. The affected/fixed version details are: Ironic: =22.0.0 =23.1.0 =25.0.0 =9.5.0 =9.8.0 =9.12.0 <9.13.1.
osv
CVE-2026-44919P4MEDIUMCVSS 4.3≥ 23.0.4, < 29.0.6≥ 30.0.0, < 32.0.2+1 more2026-05-14
CVE-2026-44919 [MEDIUM] CWE-696 CVE-2026-44919: In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.
ghsanvd
CVE-2026-44916P4LOWCVSS 3.0≥ 17.0.0, < 26.1.7≥ 27.0.0, < 29.0.6+2 more2026-05-08
CVE-2026-44916 [LOW] CWE-1336 CVE-2026-44916: In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_templa
In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.
nvd
CVE-2025-44021P4LOWCVSS 2.8≥ 24, < 24.1.3≥ 25, < 26.1.1+1 more2025-05-08
CVE-2025-44021 [LOW] CWE-22 CVE-2025-44021: OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handlin
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, b
ghsanvdosv