A AegiFlow
MEDIUMCVSS 6.3

CVE-2026-90461

CVE-2026-90461 updated by NVD

Modified
2026-09-16
Sources
nvd

Summary

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.