HIGH8.2CVE-2026-54423In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use… from 0
HIGH7.5CVE-2026-43003OpenStack Ironic Python Agent Includes Functionality from Untrusted Control Sphere from 0
MEDIUM6.8CVE-2026-54421In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can retur… from 0
MEDIUM6.5OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive infor…
from 0, < 1:4.2.2-1
MEDIUM5.5OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
from 0
MEDIUM4.9OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a…
from 0
MEDIUM4.3In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, in which a crafted i…
from 0
LOW3.0In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.
from 0
LOW2.8OpenStack Ironic fails to restrict paths used for file:// image URLs
from 0