Vulnerability Description
In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.
CVSS Score
3.0
LOW
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
Related Weaknesses (CWE)
References
- https://bugs.launchpad.net/ironic/+bug/2148307
- https://security.openstack.org/ossa/OSSA-2026-012.html
- http://www.openwall.com/lists/oss-security/2026/05/11/7
FAQ
What is CVE-2026-44916?
CVE-2026-44916 is a vulnerability with a CVSS score of 3.0 (LOW). In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.
How severe is CVE-2026-44916?
CVE-2026-44916 has been rated LOW with a CVSS base score of 3.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-44916?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.