OpenStack Ironic API Vulnerability Allows Service Disruption by Malicious Users
CVE-2026-50589

5.3MEDIUM

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
4 June 2026

What is CVE-2026-50589?

In versions of OpenStack Ironic before 37.0.0, an unauthenticated attacker can exploit a weakness in the API by submitting a specially crafted JSON string. This malicious input can lead to a crash of the service, thereby disrupting normal operations. It underscores the importance of securing API endpoints against unauthorized access and validating input data to prevent service denial.

Affected Version(s)

Ironic 32.0.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.