Home

Description

In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.

PUBLISHED Reserved 2026-06-04 | Published 2026-06-04 | Updated 2026-06-09 | Assigner mitre




MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Problem types

CWE-770 Allocation of Resources Without Limits or Throttling

Product status

Default status
unaffected

32.0.0 (semver) before 37.0.0
unknown

References

bugs.launchpad.net/ironic/+bug/2154288 exploit

www.openwall.com/lists/oss-security/2026/06/06/2

bugs.launchpad.net/ironic/+bug/2154288

wiki.openstack.org/wiki/OSSN/OSSN-0099

cve.org (CVE-2026-50589)

nvd.nist.gov (CVE-2026-50589)

Download JSON