In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.
References
Configurations
No configuration.
History
20 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
12 May 2026, 00:17
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing. |
11 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
08 May 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-08 07:16
Updated : 2026-05-20 16:16
NVD link : CVE-2026-44916
Mitre link : CVE-2026-44916
CVE.ORG link : CVE-2026-44916
JSON object : View
Products Affected
No product.
CWE
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
