VDB
Sign up
HIGH7.5

PYSEC-2026-216

Quick fix

PYSEC-2026-216 — ironic: upgrade to the fixed version with the command below.

pip install --upgrade 'ironic>=37.0.0'

Details

In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/ironic
Introduced in: 32.0.0Fixed in: 37.0.0
Fixpip install --upgrade 'ironic>=37.0.0'

References