CVE-2026-44919

MEDIUM

OpenStack Ironic - Denial of Service via Infinite Loop in Checksum Calculation

Title source: llm
STIX 2.1

Description

In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.

Scores

CVSS v3 4.3
EPSS 0.0001
EPSS Percentile 2.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-696
Status published
Products (5)
OpenStack/Ironic < a3f6d735ac3642ab95b49142c7305f072ae748d0
OpenStack/Ironic 23.0.4 - 29.0.6
OpenStack/Ironic 30.0.0 - 32.0.2
OpenStack/Ironic 33.0.0 - 35.0.2
pypi/ironic 0 - 36.0.0PyPI
Published May 14, 2026
Tracked Since May 14, 2026