CVE-2026-44916
EUVD-2026-2853108.05.2026, 07:16
In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openstack | ironic | 17.0.0 ≤ 𝑥 < 26.1.7 |
| openstack | ironic | 27.0.0 ≤ 𝑥 < 29.0.6 |
| openstack | ironic | 30.0.0 ≤ 𝑥 < 32.0.2 |
| openstack | ironic | 33.0.0 ≤ 𝑥 < 35.0.2 |
𝑥
= Vulnerable software versions
Debian Releases