CVE-2026-90461
EUVD-2026-7675111.09.2026, 22:16
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| openstack | ironic | 24.0.0 ≤ 𝑥 ≤ 29.0.6 | CNA |
| openstack | ironic | 30.0.0 ≤ 𝑥 ≤ 32.0.1 | CNA |
| openstack | ironic | 33.0.0 ≤ 𝑥 ≤ 35.0.1 | CNA |
| openstack | ironic | 36.0.0 ≤ 𝑥 ≤ 38.0.0 | CNA |
Debian Releases