CVE-2026-50589: [OSSN-0099] Denial of Service in OpenStack Ironic under duced process stack size (CVE-2026-50589)
Published Jun 4, 2026
·Updated
In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.
Affected Software
2 affected components
Openstack OpenStack Ironic>=32<37.0.0
Openstack Ironic>=32.0.0<37.0.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenStack Ironicto a version that resolves this vulnerability.Fixed in 37.0.0
Event History
Jun 4, 2026
CVE Published
via MITRE·11:59 PM
Data Sourced
via MITRE·11:59 PM
DescriptionSeverityWeakness
Jun 5, 2026
Data Sourced
via NVD·12:17 AM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·01:01 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-50589?
CVE-2026-50589 has a medium severity rating of 5.3.
2
How do I fix CVE-2026-50589?
To mitigate CVE-2026-50589, update OpenStack Ironic to version 35.0.2 or later.
3
What impact does CVE-2026-50589 have on systems?
CVE-2026-50589 allows an unauthenticated user to crash affected OpenStack Ironic services.
4
In which versions of OpenStack Ironic is CVE-2026-50589 found?
CVE-2026-50589 affects OpenStack Ironic versions 32 through 35.0.1.
5
Who is affected by CVE-2026-50589?
Any OpenStack Ironic deployment using the affected versions is vulnerable to CVE-2026-50589.