Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 12 May 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Template Injection via Unsandboxed ks_template Rendering in OpenStack Ironic |
Tue, 12 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Ironic through 35.x, instance_info['ks_template'] is rendered without sandboxing. | In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing. |
| CPEs | cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* |
Mon, 11 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 08 May 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 08 May 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Template Injection via Unsandboxed ks_template Rendering in OpenStack Ironic | |
| First Time appeared |
Openstack
Openstack ironic |
|
| Vendors & Products |
Openstack
Openstack ironic |
Fri, 08 May 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Ironic through 35.x, instance_info['ks_template'] is rendered without sandboxing. | |
| Weaknesses | CWE-1336 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-11T23:50:11.941Z
Reserved: 2026-05-08T06:38:36.747Z
Link: CVE-2026-44916
Updated: 2026-05-08T12:50:32.076Z
Status : Awaiting Analysis
Published: 2026-05-08T07:16:29.163
Modified: 2026-05-12T00:17:03.067
Link: CVE-2026-44916
No data.
OpenCVE Enrichment
Updated: 2026-05-12T03:00:06Z