
OSSA-2026-010,CVE-2026-42997: OpenStack Ironic: Credential Forwarding to Arbitrary Endpoints via iDrac Configuration Molds Feature https://www.openwall.com/lists/oss-security/2026/05/05/10 A user invoking molds can request authorization to be sent to a remote endpoint. URL is user-controlled.
Post summary
The message announces a new vulnerability in OpenStack Ironic where iDrac configuration molds allow user‑controlled URLs to forward credentials to arbitrary endpoints, but it provides no PoC, exploit, patch, or evidence of active exploitation.


