CVE-2026-42510
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
highEPSS 0.6%
Description
Metrics
Severity
high
91.83
no public PoC known
6.6
Published
2026-07-13 15:02 UTC
CWE-829
Weakness classes (CWE)
CWE-829Base
Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-08-20 01:16 UTC· af854a3a-2127-422b-91ae-364da2661108
- Reference: http://www.openwall.com/lists/oss-security/2026/08/19/6
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
openstack
ironic27.0.0 – 29.0.5
openstack
ironic30.0.0 – 32.0.1
openstack
ironic33.0.0 – 35.0.1
openstack
ironic4.3.0 – 26.1.6
References & sources
- https://nvd.nist.gov/vuln/detail/CVE-2026-42510advisory
- https://bugs.launchpad.net/ironic/+bug/2148331web
- https://github.com/openstack/ironicpackage
- https://security.openstack.org/ossa/OSSA-2026-008.htmlweb
- http://www.openwall.com/lists/oss-security/2026/04/30/1web
- https://pypi.org/project/ironicpackage
- https://github.com/advisories/GHSA-wqpv-c3pp-3m58advisory
- http://www.openwall.com/lists/oss-security/2026/08/19/6
IDCVE-2026-42510