HIGH7.5CVE-2016-4985OpenStack Ironic Exposure of Sensitive Information to an Unauthorized Actor from 0, < 4.2.5
HIGH7.5CVE-2016-4985OpenStack Ironic Exposure of Sensitive Information to an Unauthorized Actor from 0, < 4.2.5, >= 5.0, < 5.1.2
MEDIUM6.6CVE-2026-42510OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere from 0, < 35.0.1
MEDIUM5.9OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
>= 17.0.0, < 26.1.7
MEDIUM5.8OpenStack Ironic allows Boot Script Injection
>= 17.0.0, < 26.1.7
MEDIUM5.3OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
>= 32.0.0, < 37.0.0
MEDIUM5.3OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
>= 32.0.0, < 37.0.0
MEDIUM5.3OpenStack Ironic fails to verify checksums of supplied image_source URLs
>= 25.0.0, < 26.1.1
MEDIUM5.3OpenStack Ironic fails to verify checksums of supplied image_source URLs
from 0, < 23.0.3, >= 23.1.0, < 24.1.3, >= 25.0.0, < 26.1.1
MEDIUM4.3OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
from 0, <= 36.0.0