In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 24 Jul 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openstack ironic-python-agent
|
|
| Vendors & Products |
Openstack ironic-python-agent
|
Fri, 24 Jul 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it. | |
| First Time appeared |
Openstack
Openstack ironic Python Agent |
|
| Weaknesses | CWE-522 | |
| CPEs | cpe:2.3:a:openstack:ironic_python_agent:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack ironic Python Agent |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-07-24T12:26:32.687Z
Reserved: 2026-06-14T03:57:25.577Z
Link: CVE-2026-54422
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-24T05:30:05Z
Weaknesses