UNKNOWN OpenStack

CVE-2026-50589

OSSN-0099: Denial of Service in Ironic under reduced process stack size

An unauthenticated malicious user could submit a specially crafted JSON string to certain endpoints on the API service or the JSON-RPC endpoint if enabled, and cause a service crash until the service is restarted. This was due to the memory allocation exceeding the stack size of the Python runtime due to Ironic's reduced default stack size prior to the initial payload validation.

Affected Products

References

Published: 2026-06-05 · Source: OpenStack · Feed updated: 2026-08-04
This unknown severity vulnerability was published on 2026-06-05 via OpenStack. Affected: ironic: >=32.0.0, <37.0.0, CVE-2026-50589.
vulnfeed aggregates 9214 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.