CVE-2026-50589: Openstack Ironic
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.
Affected products
- Openstack Ironic: from 32.0.0, before 37.0.0 (fixed in 37.0.0)
Published 2026-06-05. Last modified 2026-07-23.