HIGH8.1
PYSEC-2026-505
Injection vulnerability that affects ironic-discoverd
Quick fix
PYSEC-2026-505 — python-ironic-inspector-client: upgrade to the fixed version with the command below.
pip install --upgrade 'python-ironic-inspector-client>=0.2.5'Details
OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask console and execute arbitrary Python code by triggering an error.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/python-ironic-inspector-client
Introduced in:
0Fixed in: 0.2.5Fix
pip install --upgrade 'python-ironic-inspector-client>=0.2.5'References
- https://nvd.nist.gov/vuln/detail/CVE-2015-5306[ADVISORY]
- https://access.redhat.com/errata/RHSA-2015:1929[WEB]
- https://access.redhat.com/errata/RHSA-2015:2685[WEB]
- https://access.redhat.com/security/cve/CVE-2015-5306[WEB]
- https://bugs.launchpad.net/ironic-inspector/+bug/1506419[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=1273698[WEB]
- https://github.com/pypa/advisory-database/tree/main/vulns/ironic-inspector/PYSEC-2015-28.yaml[WEB]
- https://opendev.org/openstack/ironic-inspector[PACKAGE]
- https://opendev.org/openstack/ironic-inspector/commit/2c64da2bee6eeea27c08eb7a94894feaa5494910[WEB]
- https://opendev.org/openstack/ironic-inspector/commit/77d0052c5133034490386fbfadfdb1bdb49aa44f[WEB]
- http://rhn.redhat.com/errata/RHSA-2015-2685.html[WEB]
- https://pypi.org/project/python-ironic-inspector-client[PACKAGE]
- https://github.com/advisories/GHSA-x64g-wjmw-w328[ADVISORY]