VYPR
Medium severity6.8NVD Advisory· Published Jun 14, 2026· Updated Jun 16, 2026

CVE-2026-54421

CVE-2026-54421

Description

In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ironicPyPI
>= 17.0.0, < 29.0.629.0.6
ironicPyPI
>= 30.0.0, < 32.0.232.0.2
ironicPyPI
>= 33.0.0, < 35.0.235.0.2
ironicPyPI
>= 36.0.0, < 37.0.137.0.1

Affected products

2

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.