Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6341-1 | ironic security update |
Wed, 20 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 12 May 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Template Injection via Unsandboxed ks_template Rendering in OpenStack Ironic |
Tue, 12 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Ironic through 35.x, instance_info['ks_template'] is rendered without sandboxing. | In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing. |
| CPEs | cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* |
Mon, 11 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 08 May 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 08 May 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Template Injection via Unsandboxed ks_template Rendering in OpenStack Ironic | |
| First Time appeared |
Openstack
Openstack ironic |
|
| Vendors & Products |
Openstack
Openstack ironic |
Fri, 08 May 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Ironic through 35.x, instance_info['ks_template'] is rendered without sandboxing. | |
| Weaknesses | CWE-1336 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-20T15:04:18.146Z
Reserved: 2026-05-08T06:38:36.747Z
Link: CVE-2026-44916
Updated: 2026-05-11T17:40:03.179Z
Status : Undergoing Analysis
Published: 2026-05-08T07:16:29.163
Modified: 2026-06-17T10:51:30.810
Link: CVE-2026-44916
No data.
OpenCVE Enrichment
Updated: 2026-05-12T03:00:06Z
Debian DSA