CVE-2026-44919: Openstack Ironic
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.
Affected products
- Openstack Ironic: from 23.0.4, before 29.0.6 (fixed in 29.0.6); from 30.0.0, before 32.0.2 (fixed in 32.0.2); from 33.0.0, before 35.0.2 (fixed in 35.0.2)
Published 2026-05-14. Last modified 2026-06-17.