UNKNOWN OpenStack

CVE-2026-44919

OSSA-2026-013: Denial of Service in Ironic under specially crafted deployment requests

Erichen of the Institute of Computing Technology at the Chinese Academy of Sciences reported a vulnerability in Ironic’s image handling code where an authenticated and appropriately authorized user could request a special device or file path be deployed, where checksum evaluation would occur in advance of file path checking being asserted. This was a change introduced as a follow-up to soften CVE-2024-47211 image handling since “files on disk” are considered artifacts placed by the deployer/mana

Affected Products

References

Published: 2026-05-19 · Source: OpenStack · Feed updated: 2026-08-04
This unknown severity vulnerability was published on 2026-05-19 via OpenStack. Affected: Ironic: >=23.0.4 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2, CVE-2026-44919, CVE-2024-47211.
vulnfeed aggregates 9214 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.