Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-44919

27
FAUCET Score

In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.

First published: May 14, 2026Last modified: May 21, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 23.0.4, < 29.0.6CPE matchmatch criteria
cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*
>= 30.0.0, < 32.0.2CPE matchmatch criteria
cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*
>= 33.0.0, < 35.0.2CPE matchmatch criteria
cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.47%
Probability of exploitation in next 30 days
EPSS Percentile
37.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0047 is in the 48th percentile among its peer group of 21,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

pipGHSA-4g73-w726-53h3medium

OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices

May 14, 2026

References

bugs.launchpad.net / ironic/+bug/2150332
ExploitIssue TrackingThird Party Advisory
opendev.org / openstack/ironic/commit/a3f6d735ac3642ab95b49142c7305f072ae748d0
Patch
security.openstack.org / ossa/OSSA-2026-013.html
PatchVendor Advisory