CVE-2026-50589
OpenStack Ironic vulnerability analysis and mitigation

Overview

CVE-2026-50589 is a Denial of Service vulnerability in OpenStack Ironic caused by insufficient JSON input validation, allowing an unauthenticated attacker to crash the service by submitting a crafted JSON string to API or JSON-RPC endpoints. It affects OpenStack Ironic versions 32.0.0 through 36.x (fixed in 37.0.0), disclosed on June 5, 2026. The vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling). CVSS v3.1 scores vary by source: NVD rates it 7.5 (High) and the CNA (MITRE) rates it 5.3 (Medium) (GitHub Advisory, Openwall).

Technical details

The root cause is that OpenStack Ironic's Python runtime uses a reduced default process stack size, and processing deeply nested or excessively large recursive JSON structures causes memory allocation to exceed the stack size before initial payload validation occurs, resulting in a service crash (CWE-770) (Openwall). An unauthenticated attacker can exploit this remotely by sending a specially crafted JSON payload — such as deeply nested objects or oversized serialized data — to any affected API endpoint or the JSON-RPC endpoint if enabled. No authentication, privileges, or user interaction are required, making this trivially automatable. The fix introduces a customized size-check middleware that validates JSON recursion depth and body size before processing, along with new configuration options ([api]/max_json_body_depth, [api]/max_json_body_size, etc.) (Openwall).

Impact

Successful exploitation results in a crash of the Ironic service (the OpenStack bare metal provisioning service), requiring a manual restart to restore availability. This is a pure availability impact with no confidentiality or integrity consequences. In environments relying on Ironic for bare metal node management, a crash could disrupt provisioning workflows, delay deployments, and potentially affect production infrastructure operations (Openwall, GitHub Advisory).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). However, CISA's SSVC assessment (added June 17, 2026) classifies the vulnerability as having a PoC exploitation status and marks it as "automatable," indicating the attack can be scripted without human interaction (NVD). The EPSS score is approximately 0.039–0.048%, placing it in the lower percentiles for near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify OpenStack deployments running Ironic versions 32.0.0–36.x using network scanning or cloud infrastructure enumeration. Determine if the Ironic API (typically port 6385) or JSON-RPC endpoint is accessible from the network.
  2. Craft malicious JSON payload: Construct a deeply nested recursive JSON structure (e.g., {"a":{"a":{"a":...}}} repeated beyond 25 levels) or an oversized JSON body exceeding the default stack allocation limits of the Python runtime.
  3. Submit payload to vulnerable endpoint: Send an HTTP POST or PUT request with the crafted JSON payload to any Ironic API endpoint (e.g., /v1/nodes) or the JSON-RPC endpoint, without providing any authentication credentials.
  4. Trigger service crash: The Ironic service processes the malformed JSON before input validation, causing memory allocation to exceed the reduced Python process stack size, resulting in a crash.
  5. Repeat for sustained DoS: Resubmit the payload after service restart to maintain denial of service until the patch is applied or a workaround is implemented (Openwall).

Indicators of compromise

  • Network: Repeated HTTP POST/PUT requests to Ironic API endpoints (default port 6385) or JSON-RPC endpoints with unusually large Content-Length headers or deeply nested JSON bodies from unexpected source IPs.
  • Logs: Ironic service logs showing Python stack overflow or memory allocation errors immediately preceding an unplanned service termination; crash traces in /var/log/ironic/ironic-api.log or equivalent.
  • Process: Unexpected termination of the ironic-api or ironic-conductor process; systemd or process supervisor logs showing repeated service restarts.
  • Application: HTTP 500 errors or connection resets on Ironic API endpoints correlated with large or malformed JSON request bodies in access logs (Openwall).

Mitigation and workarounds

Upgrade OpenStack Ironic to version 37.0.0 or later, which introduces a size-check middleware enforcing JSON recursion depth and body size limits (Openwall). Branch-specific patches are available for 2026.1/gazpacho, 2025.2/flamingo, bugfix/34.0, and bugfix/33.0 via OpenDev review links provided in OSSN-0099. As an immediate workaround for operators unable to patch, set the environment variable IRONIC_THREAD_STACK_SIZE=8388608 before starting Ironic services to increase the process stack size. After patching, review and tune the new configuration options: [api]/max_json_body_depth (default 25), [api]/max_json_body_size (default 1024 KiB), [api]/max_json_body_size_provision (default 64 MiB), and [api]/max_json_body_size_inspection (default 16 MiB). Additionally, restrict network access to Ironic API and JSON-RPC endpoints to trusted clients only (Openwall, OpenStack OSSN).

Community reactions

The vulnerability was disclosed by Jay Faulkner (G-Research Open Source Software) and Julia Kreger (Red Hat) via the OpenStack Security mailing list and OSSN-0099. Credits for discovery were given to Dmitry Tantsur (Red Hat), Tuomo Tanskanen (Ericsson Software Technology), and the Metal3.io Security Team (Openwall). No significant broader media coverage or notable social media reactions have been identified beyond standard vulnerability database aggregation.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

ironic

Fixed

sid

ironic: 1:35.0.1-5

Fixed

trixie

ironic

Fixed

Ubuntu

Unknown

bionic (esm-apps)

ironic

Unknown

devel

ironic

Unknown

focal (esm-apps)

ironic

Unknown

jammy

ironic

Unknown

jammy (esm-apps)

ironic

Unknown

noble

ironic

Unknown

noble (esm-apps)

ironic

Unknown

resolute

ironic

Unknown

RHEL / CentOS

Affected

OpenShift

Not Affected

SourceThis report was generated using AI

Related OpenStack Ironic vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48681HIGH8.1
  • OpenStack Ironic logoOpenStack Ironic
  • ironic
NoYesJun 04, 2026
CVE-2026-46447HIGH7.7
  • OpenStack Ironic logoOpenStack Ironic
  • ironic
NoYesJun 03, 2026
CVE-2026-50589HIGH7.5
  • OpenStack Ironic logoOpenStack Ironic
  • ironic
NoYesJun 05, 2026
CVE-2026-54421MEDIUM6.8
  • OpenStack Ironic logoOpenStack Ironic
  • ironic
NoYesJun 14, 2026
CVE-2026-44919MEDIUM6.5
  • OpenStack Ironic logoOpenStack Ironic
  • ironic
NoYesMay 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management