CVE-2026-54422: Openstack Ironic Python Agent

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

Affected products

  • Openstack Ironic Python Agent: from 10.2.0, before 10.2.3 (fixed in 10.2.3); from 11.0.0, before 11.2.1 (fixed in 11.2.1); from 11.3.0, before 11.5.1 (fixed in 11.5.1)

Published 2026-07-24. Last modified 2026-09-09.