CVE-2026-50589: Openstack Ironic

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.

Affected products

  • Openstack Ironic: from 32.0.0, before 37.0.0 (fixed in 37.0.0)

Published 2026-06-05. Last modified 2026-07-23.