- Package:
- src:ironic
- Source:
- src:ironic
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-10-09 14:31:06 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for ironic. CVE-2026-90461[0]: | OpenStack Ironic through 38.0.0 may send a username and password to | an unexpected remote host when Image Service is configured for | HTTP(S) Basic Authentication. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-90461 https://www.cve.org/CVERecord?id=CVE-2026-90461 [1] https://bugs.launchpad.net/ironic/+bug/2162816 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hello, Bug #1148451 in ironic reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/ironic/-/commit/c98456fe48bb6ec27636f1bfdca35f99e329ac04 (this message was generated automatically) -- Greetings https://bugs.debian.org/1148451
Hello, Bug #1148451 in ironic reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/ironic/-/commit/0ff2336fe1c06b464f26773435ad1a9899742826 ------------------------------------------------------------------------ * CVE-2026-90461: Ironic may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication. Applied upstream patch: "Add image_server_auth_hosts to restrict credential scope" (Closes: #1148451): - CVE-2026-90461_Add-image_server_auth_hosts-to-restrict-credentia....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1148451
Hello, Bug #1148451 in ironic reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/ironic/-/commit/91f79177b1a4d4ef8a9b96cc26bd6f2f5c9e245d ------------------------------------------------------------------------ * CVE-2026-90461: Ironic may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication. Applied upstream patch: "Add image_server_auth_hosts to restrict credential scope" (Closes: #1148451): - CVE-2026-90461_Add-image_server_auth_hosts-to-restrict-credentia....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1148451
Hello, Bug #1148451 in ironic reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/ironic/-/commit/243463a99a1c0ca3cb5e060f20686138d66e7395 ------------------------------------------------------------------------ * CVE-2026-90461: Ironic may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication. Applied upstream patch: "Add image_server_auth_hosts to restrict credential scope" (Closes: #1148451): - CVE-2026-90461_Add-image_server_auth_hosts-to-restrict-credentia....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1148451
Hello, Bug #1148451 in ironic reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/ironic/-/commit/9e15126eefe52bbe5f61bc9e74298ec679c51abe ------------------------------------------------------------------------ * CVE-2026-90461: Ironic may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication. Applied upstream patch: "Add image_server_auth_hosts to restrict credential scope" (Closes: #1148451): - CVE-2026-90461_Add-image_server_auth_hosts-to-restrict-credentia....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1148451
Hello, Bug #1148451 in ironic reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/ironic/-/commit/b28f851c6861eaf370ff28eb3c340f636d338be4 ------------------------------------------------------------------------ * CVE-2026-90461: Ironic may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication. Applied upstream patch: "Add image_server_auth_hosts to restrict credential scope" (Closes: #1148451): - CVE-2026-90461_Add-image_server_auth_hosts-to-restrict-credentia....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1148451
We believe that the bug you reported is fixed in the latest version of
ironic, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1148451@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated ironic package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 21 Sep 2026 12:07:01 +0200
Source: ironic
Architecture: source
Version: 1:39.0.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1148451
Changes:
ironic (1:39.0.0-1) unstable; urgency=medium
.
* New upstream release:
- Addresses CVE-2026-90461 (Closes: #1148451).
* Fixed (build-)depends for this release.
* Removed json-rpc_Rename_TLS_options.patch applied upstream.
Checksums-Sha1:
72c6e33c112918813d060d41587fb47dca06ab1a 4101 ironic_39.0.0-1.dsc
6dc648ab4eab0cfc17596bb0602bcf60114a15ce 2120808 ironic_39.0.0.orig.tar.xz
60741473e7e51a3c890a0d9c3f87ada4740325d9 20472 ironic_39.0.0-1.debian.tar.xz
5f4162598cd1ff74b03f1f265dd2096e2696b961 22231 ironic_39.0.0-1_amd64.buildinfo
Checksums-Sha256:
222860217198318b212bbc24c6611f6625c1e10d8c3f4715b5f96b8f1e697747 4101 ironic_39.0.0-1.dsc
78de50a53c3cbddb4c23c49d2c727811aa2b478b149344e29194da03659a64c1 2120808 ironic_39.0.0.orig.tar.xz
3ee063e81673119e5268a6269c19285e766d8eaa775e2e8c982a769b020a3acf 20472 ironic_39.0.0-1.debian.tar.xz
7d5114526ea34ea3c89ffb6ffb70d0f2ddb174148a259c3d6b8c8209037986b8 22231 ironic_39.0.0-1_amd64.buildinfo
Files:
1ff1849cc1c202bb80acc701a8a1f96e 4101 net optional ironic_39.0.0-1.dsc
d4727030488d1fe127a9a32774faedbf 2120808 net optional ironic_39.0.0.orig.tar.xz
e7ec28d974fcbdb389d225c254229244 20472 net optional ironic_39.0.0-1.debian.tar.xz
afcf7d96c7b7740c5a3be3ecb9b88948 22231 net optional ironic_39.0.0-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqxBNgACgkQ1BatFaxr
Q/6smw//fEGVfeEuwsW2I8Kfd0rJUc0cuIbOsOdAD06pOZPy1AwZenN3uaUc7JwG
E8WDDbIEhUA+VD85EufxRZmtKhy6Ms2hLqSdXs+oFX4l0rIKafiFk8IJHXIYHjn4
XB8bxHQQsOq5HeYLHbWJcGvlkhWggz43giWZyM2rv0n1pSpA6obk0PBVZOLL0ejg
OHtGoqIRW/AXTZAokTdRmJP5+fhUgbKanWBrR5Auw+ipoOWV7OvzP7c3gmW+XI1B
jvwFmD1cMzhk7JKgCv3K1WEwR+BLxzWyu4Yw84bYMctyKXnf+N3blvTKNLF4evdW
2ksYKLTgsQ5JnUKuCvtA95nekgGkg5JipH34n3tjKrI5HmPj+teh+YYB1D0XDuiR
QDDfRPxS0Vj035g47N1h1+uqMp8S2dAReJJ1hOyE6hBeKoE8BljO5bmzYBaZMA/6
feVXNVxojjaRnKYCb1CGRQWztNOjsPTlb8krhgYURKAV+Tvk6tExva02j7Neg0Zb
FYEhKBmUBKL6t4J6DuWr430ec2cTf5YXRhzQJIOAqvGUwEwlBBBAfe7SBbBJv2nS
1nn/KhOYYu17FfrdqKSvplHjXU1a37O7jaMgxbF6rFejjILHDWJnb2CHX+Cd6MQn
yLt9Ihub2wmqZZfU9R5MRPve/fn2JFXnRP3nd9HXoAEQq42Htho=
=g5WP
-----END PGP SIGNATURE-----