GHSA-q3g8-rjrx-59phMediumCVSS 5.3
OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
🔗 CVE IDs covered (1)
📋 Description
In OpenStack Ironic 32.0.0 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.
🎯 Affected products1
- pip/ironic:>= 32.0.0, < 37.0.0
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-50589
- https://bugs.launchpad.net/ironic/+bug/2154288
- https://wiki.openstack.org/wiki/OSSN/OSSN-0099
- http://www.openwall.com/lists/oss-security/2026/06/06/2
- https://access.redhat.com/security/cve/CVE-2026-50589
- https://bugzilla.redhat.com/show_bug.cgi?id=2485353
- https://github.com/pypa/advisory-database/tree/main/vulns/ironic/PYSEC-2026-216.yaml
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50589.json
- https://github.com/advisories/GHSA-q3g8-rjrx-59ph