CVE-2026-90461
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
- Published Sep 11, 2026
- CVSS 6.3 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)