Security Advisory
CVE-2026-90461
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.