CVE-2026-50589
EUVD-2026-3477405.06.2026, 00:17
In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openstack | ironic | 32.0.0 ≤ 𝑥 < 37.0.0 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration
- CWE-770 - Allocation of Resources Without Limits or ThrottlingThe software allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
- CWE-502 - Deserialization of Untrusted DataThe application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
References