OpenStack Ironic Python Agent
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in OpenStack Ironic Python Agent.
By the Year
In 2026 there have been 2 vulnerabilities in OpenStack Ironic Python Agent with an average score of 6.4 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 6.35 |
It may take a day or so for new Ironic Python Agent vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent OpenStack Ironic Python Agent Security Vulnerabilities
CVE-2026-66138: Ironic-Python-Agent pre-11.6.0 ntp_server shell exec
CVE-2026-66138
7.2 - High
- July 24, 2026
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.
Shell injection
OpenStack Ironic Python Agent 11.5.0 Credential Leak in bootc
CVE-2026-54422
5.5 - Medium
- July 24, 2026
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
Insufficiently Protected Credentials
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for OpenStack Ironic Python Agent or by OpenStack? Click the Watch button to subscribe.