UNKNOWN OpenStack

CVE-2026-71201

OSSA-2026-033: Portgroup shard filter bypasses project scope

Chen YuXiang of Institute of Computing Technology, Chinese Academy of Sciences reported an issue in Ironic’s API. When a project reader requests a list of portgroups filtered by shard, all portgroups in that shard are returned, not just those in their project. This is a similar vulnerability to the one originally advisoried in OSSA-2026-026 – that issue impacted ports; this impacts portgroups. Patches ¶ https://review.opendev.org/999762 (2026.1/gazpacho) https://review.opendev.org/999656 (2026.2

Affected Products

References

Published: 2026-08-05 · Source: OpenStack · Feed updated: 2026-09-19
This unknown severity vulnerability was published on 2026-08-05 via OpenStack. Affected: Ironic: >=34.0.0 <35.0.2, >=36.0.0 <38.0.1, CVE-2026-71201.
vulnfeed aggregates 14146 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.