Home

Description

In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.

PUBLISHED Reserved 2026-05-08 | Published 2026-05-08 | Updated 2026-05-20 | Assigner mitre




LOW: 3.0CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N

Problem types

CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine

Product status

Default status
unaffected

17.0.0 (semver) before 26.1.7
affected

27.0.0 (semver) before 29.0.6
affected

30.0.0 (semver) before 32.0.2
affected

33.0.0 (semver) before 35.0.2
affected

References

www.openwall.com/lists/oss-security/2026/05/11/7

bugs.launchpad.net/ironic/+bug/2148307

security.openstack.org/ossa/OSSA-2026-012.html

cve.org (CVE-2026-44916)

nvd.nist.gov (CVE-2026-44916)

Download JSON