CVE-2026-54421: OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
(updated )
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-54421 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →