PYSEC-2026-3852

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/ironic/PYSEC-2026-3852.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-3852
Aliases
Published
2026-09-10T09:44:49Z
Modified
2026-09-10T12:15:03Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
Details

In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.

References

Affected packages

PyPI / ironic

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
17.0.0
Fixed
29.0.6
Introduced
30.0.0
Fixed
32.0.2
Introduced
33.0.0
Fixed
35.0.2
Introduced
36.0.0
Fixed
37.0.1

Affected versions

17.*
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0
18.*
18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0
19.*
19.0.0
20.*
20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0
21.*
21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3
21.4.4
22.*
22.0.0
22.1.0
23.*
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
24.*
24.0.0
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
25.*
25.0.0
26.*
26.0.0
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
27.*
27.0.0
28.*
28.0.0
29.*
29.0.0
29.0.1
29.0.2
29.0.3
29.0.4
29.0.5
30.*
30.0.0
31.*
31.0.0
32.*
32.0.0
32.0.1
33.*
33.0.0
34.*
34.0.0
35.*
35.0.0
35.0.1
36.*
36.0.0
37.*
37.0.0

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/ironic/PYSEC-2026-3852.yaml"