GHSA-wqpv-c3pp-3m58

Suggest an improvement
Source
https://github.com/advisories/GHSA-wqpv-c3pp-3m58
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-wqpv-c3pp-3m58/GHSA-wqpv-c3pp-3m58.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wqpv-c3pp-3m58
Aliases
  • CVE-2026-42510
Published
2026-04-28T06:30:29Z
Modified
2026-06-08T20:15:13.376045650Z
Severity
  • 6.6 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Details

OpenStack Ironic through 25.0.0 allows ipmitool execution in a non-default configuration that has a console interface.

Database specific
{
    "nvd_published_at": "2026-04-28T06:16:04Z",
    "cwe_ids": [
        "CWE-829"
    ],
    "github_reviewed_at": "2026-05-06T19:41:11Z",
    "github_reviewed": true,
    "severity": "MODERATE"
}
References

Affected packages

PyPI / ironic

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
25.0.0

Affected versions

0.*
0.0
9.*
9.1.6
9.1.7
10.*
10.1.7
10.1.8
10.1.9
10.1.10
11.*
11.1.1
11.1.2
11.1.3
11.1.4
12.*
12.0.0
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0
13.*
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7
14.*
14.0.0
15.*
15.0.0
15.0.1
15.0.2
15.1.0
15.2.0
16.*
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0
17.*
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.*
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.*
19.0.0
20.*
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.*
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.*
22.0.0
22.1.0
23.*
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.*
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.*
25.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-wqpv-c3pp-3m58/GHSA-wqpv-c3pp-3m58.json"