CVE-2026-90461

Summary

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

Affected Software

VendorProductVersion RangeStatus
OpenStackIronic24.0.0 <= 29.0.6affected
OpenStackIronic30.0.0 <= 32.0.1affected
OpenStackIronic33.0.0 <= 35.0.1affected
OpenStackIronic36.0.0 <= 38.0.0affected

Weaknesses

  • CWE-923: CWE-923 Improper Restriction of Communication Channel to Intended Endpoints

References