---
id: CVE-2026-42997
title: An issue was discovered in idrac in OpenStack Ironic before 35.0.1
summary: >-
  An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During
  import, a user invoking molds can request authorization to be sent to a remote
  endpoint. The credential forwarded is a time-limited Keystone token (which
  provides…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-669
  - CWE-201
vendor: openstack
product: ironic
affected:
  - 'ironic >= 17.0.0, < 26.1.6'
  - 'ironic >= 27.0.0, < 29.0.5'
  - 'ironic >= 30.0.0, < 32.0.1'
  - 'ironic >= 33.0.0, < 35.0.1'
patched:
  - ironic 35.0.1
published: '2026-05-05'
updated: '2026-07-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42997'
references:
  - url: 'https://security.openstack.org/ossa/OSSA-2026-010.html'
    label: cve@mitre.org
  - url: 'https://www.openwall.com/lists/oss-security/2026/05/05/10'
    label: cve@mitre.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/05/10'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/cve/CVE-2026-42997'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2466844'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42997.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42997'
  - url: 'https://github.com/openstack/ironic-python-agent'
tags:
  - nvd
  - osv
  - pip
epss: 0.00544
epssPercentile: 0.43215
ingestedAt: '2026-07-08T13:51:10.479Z'
aliases:
  - GHSA-54w4-233h-x86g
  - PYSEC-2026-2526
ecosystem: pip
---

## Overview

An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1.

## Affected

- `ironic >= 17.0.0, < 26.1.6`
- `ironic >= 27.0.0, < 29.0.5`
- `ironic >= 30.0.0, < 32.0.1`
- `ironic >= 33.0.0, < 35.0.1`

## Remediation

Upgrade past the affected range:

- `ironic 35.0.1`

## Package advisory (CVE-2026-42997)

Affected packages:

- `ironic-python-agent >= 33.0.0, < 35.0.1`
- `ironic-python-agent >= 30.0.0, < 32.0.1`
- `ironic-python-agent >= 27.0.0, < 29.0.5`
- `ironic-python-agent < 26.1.6`

Patched in:

- `ironic-python-agent 35.0.1`
- `ironic-python-agent 32.0.1`
- `ironic-python-agent 29.0.5`
- `ironic-python-agent 26.1.6`

Source: https://osv.dev/vulnerability/GHSA-54w4-233h-x86g
