Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-50589

Опубликовано: 04 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.

A flaw was found in OpenStack Ironic. An unauthenticated malicious user could exploit this vulnerability by submitting a specially crafted JSON (JavaScript Object Notation) string to certain API (Application Programming Interface) or JSON-RPC (Remote Procedure Call) service endpoints. This could lead to a service crash, resulting in a Denial of Service (DoS) for affected systems.

Меры по смягчению последствий

To reduce the risk of exploitation, restrict network access to the OpenStack Ironic API and JSON-RPC service endpoints. Configure firewall rules to permit connections only from trusted hosts and networks that require access to Ironic services. This operational control limits the attack surface by preventing unauthenticated remote attackers from reaching the vulnerable endpoints. A restart of the Ironic services may be required for firewall changes to take full effect, which could temporarily impact bare metal provisioning operations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openstack-ironicAffected
Red Hat OpenStack Platform 16.2openstack-ironicAffected
Red Hat OpenStack Platform 17.1openstack-ironicAffected
Red Hat OpenStack Platform 18.0openstack-ironicAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2485353openstack-ironic: OpenStack Ironic: Denial of Service via crafted JSON string

EPSS

Процентиль: 35%
0.00433
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
2 месяца назад

In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.

CVSS3: 5.3
nvd
2 месяца назад

In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.

CVSS3: 5.3
debian
2 месяца назад

In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious use ...

CVSS3: 5.3
github
2 месяца назад

In OpenStack Ironic 32 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.

EPSS

Процентиль: 35%
0.00433
Низкий

7.5 High

CVSS3