https://seclists.org/oss-sec/2026/q2/611: [OSSA-2026-013] Ironic: Denial of Service via specially crafted deployment quests (CVE-2026-44919)
Published May 19, 2026
·Updated
Affected Software
1 affected component
Openstack Ironic>=23.0.4<29.0.6, >=30.0.0<32.0.2, >=33.0.0<35.0.2
Frequently Asked Questions
1
What is the severity of CVE-2026-44919?
CVE-2026-44919 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2026-44919?
To mitigate CVE-2026-44919, update OpenStack Ironic to a version that is not affected by this vulnerability.
3
Which versions are affected by CVE-2026-44919?
CVE-2026-44919 affects OpenStack Ironic versions >=23.0.4 <29.0.6, >=30.0.0 <32.0.2, and >=33.0.0 <35.0.2.
4
What type of attack does CVE-2026-44919 allow?
CVE-2026-44919 allows an attacker to perform a denial of service attack via specially crafted deployment quests.
5
When was CVE-2026-44919 published?
CVE-2026-44919 was published on May 19, 2026.