CVE-2026-50589: OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
(updated )
In OpenStack Ironic 32.0.0 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.
References
- access.redhat.com/security/cve/CVE-2026-50589
- bugs.launchpad.net/ironic/+bug/2154288
- bugzilla.redhat.com/show_bug.cgi?id=2485353
- github.com/advisories/GHSA-q3g8-rjrx-59ph
- github.com/pypa/advisory-database/tree/main/vulns/ironic/PYSEC-2026-216.yaml
- nvd.nist.gov/vuln/detail/CVE-2026-50589
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50589.json
- wiki.openstack.org/wiki/OSSN/OSSN-0099
Code Behaviors & Features
Detect and mitigate CVE-2026-50589 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →