Ironic Python Agent OpenStack Ironic Python Agent

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in OpenStack Ironic Python Agent.

By the Year

In 2026 there have been 2 vulnerabilities in OpenStack Ironic Python Agent with an average score of 6.4 out of ten.

Year Vulnerabilities Average Score
2026 2 6.35

It may take a day or so for new Ironic Python Agent vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent OpenStack Ironic Python Agent Security Vulnerabilities

CVE-2026-66138: Ironic-Python-Agent pre-11.6.0 ntp_server shell exec
CVE-2026-66138 7.2 - High - July 24, 2026

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.

Shell injection

OpenStack Ironic Python Agent 11.5.0 Credential Leak in bootc
CVE-2026-54422 5.5 - Medium - July 24, 2026

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

Insufficiently Protected Credentials

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for OpenStack Ironic Python Agent or by OpenStack? Click the Watch button to subscribe.

OpenStack
Vendor

subscribe