Impact
Clients can send a specially crafted JSON payload to specific endpoints in the Ironic API or JSON‑RPC service without authentication, which leads to an unhandled exception and causes the service to crash. The flaw is an instance of resource exhaustion (CWE‑770) and results in a denial of service rather than data compromise.
Affected Systems
The vulnerability exists in OpenStack Ironic versions 32 through 35.0.1. Versions earlier than 32 or later than 35.0.1 are not affected according to the vendor's data.
Risk and Exploitability
With a CVSS score of 5.3, the risk is moderate. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no large‑scale exploitation has been observed. The likely attack vector is remote; an unauthenticated attacker can issue malicious JSON to the public API endpoints and force a crash, disrupting availability of the Ironic service.
OpenCVE Enrichment