CVE-2026-44916

In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.
Configurations

No configuration.

History

20 May 2026, 16:16

Type Values Removed Values Added
References
  • () https://security.openstack.org/ossa/OSSA-2026-012.html -

12 May 2026, 00:17

Type Values Removed Values Added
Summary (en) In OpenStack Ironic through 35.x, instance_info['ks_template'] is rendered without sandboxing. (en) In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.

11 May 2026, 18:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/05/11/7 -

08 May 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-08 07:16

Updated : 2026-05-20 16:16


NVD link : CVE-2026-44916

Mitre link : CVE-2026-44916

CVE.ORG link : CVE-2026-44916


JSON object : View

Products Affected

No product.

CWE
CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine