OpenStack disclosed that Ironic Python Agent (IPA) versions 3.7.0 through 11.6.1 can unexpectedly fall back to multicast DNS (mDNS) when the agent boots without a valid API URL, allowing it in rare cases to discover and connect to an unintended Ironic API service on the local network. The issue primarily affects specialized bare-metal bootstrap workflows such as virtual media or USB-based provisioning, because standard Ironic-managed deployments normally provide a valid API URL and do not rely on discovery behavior.
To reduce the risk, OpenStack changed IPA so mDNS fallback is no longer automatic and must be explicitly enabled with settings such as ipa-api-url=mdns or ipa-use-mdns=True. Reporting on the disclosure also highlighted a separate July fix in the same component, where the ntp_server value could be inserted into a shell command without proper validation, creating a potential root-level command injection path during early boot; together, the issues underscore the security sensitivity of pre-OS provisioning paths. No CVE was assigned to the mDNS fallback issue, and operators were advised to verify that IPA boots are managed by Ironic and to review any environments that intentionally depend on mDNS before upgrading.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On July 23, 2026, OpenStack fixed a separate Ironic Python Agent vulnerability in which the ntp_server setting was inserted into a shell command without proper validation, enabling root-privileged command injection during provisioning if an attacker controlled that value.
OpenStack published security notice OSSN-0104 warning that ironic-python-agent versions 3.7.0 through 11.6.1 could unexpectedly fall back to mDNS when booted without a valid API URL, potentially allowing the agent to be redirected to a different Ironic API service. The notice said no CVE was assigned and advised operators to ensure IPA boots are properly managed and explicitly enable mDNS only where needed.
OpenStack updated the 2026.2 development branch of ironic-python-agent so multicast DNS fallback no longer occurs automatically and instead requires explicit opt-in via settings such as ipa-api-url=mdns or ipa-use-mdns=True. The change was described as backwards incompatible and was not merged into stable branches.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.