In OpenStack Ironic 32 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://bugs.launchpad.net/ironic/+bug/2154288 |
|
History
Fri, 05 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openstack
Openstack ironic |
|
| Vendors & Products |
Openstack
Openstack ironic |
Fri, 05 Jun 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Malicious JSON Crash in OpenStack Ironic |
Fri, 05 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Ironic 32 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash. | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-04T23:59:20.118Z
Reserved: 2026-06-04T23:59:19.739Z
Link: CVE-2026-50589
No data.
Status : Received
Published: 2026-06-05T00:17:09.213
Modified: 2026-06-05T00:17:09.213
Link: CVE-2026-50589
No data.
OpenCVE Enrichment
Updated: 2026-06-05T04:30:31Z
Weaknesses