CVE-2026-44919: [OSSA-2026-013] Ironic: Denial of Service via specially crafted deployment quests (CVE-2026-44919)
Published May 14, 2026
·Updated
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.
Affected Software
1 affected component
Openstack Ironic<=35.x (before a3f6d73)
Event History
May 14, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44919?
CVE-2026-44919 is classified as a high severity vulnerability due to the potential for an infinite loop affecting system resources.
2
How do I fix CVE-2026-44919?
To fix CVE-2026-44919, upgrade OpenStack Ironic to version a3f6d73 or later.
3
What does CVE-2026-44919 affect?
CVE-2026-44919 affects OpenStack Ironic versions up to 35.x before a3f6d73.
4
What type of issue is CVE-2026-44919?
CVE-2026-44919 involves an infinite loop in checksum calculations during image handling.
5
Can CVE-2026-44919 lead to a denial of service?
Yes, CVE-2026-44919 can lead to a denial of service due to resource exhaustion from the infinite loop.