PT-2026-79269 · Openstack · Openstack Glance

CVE-2026-77648

·

Published

2026-08-20

·

Updated

2026-08-20

CVSS v3.1

2.2

Low

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Glance versions prior to 32.0.1
Description The '/v2/tasks' API accepts tasks with the type parameter set to 'import' that bypass import filtering opts. This allows an administrator to perform Server-Side Request Forgery (SSRF), a technique where an attacker induces a server to make requests to an unintended location, to fetch internal URLs from the Glance service network using the http:// or https:// protocols.
Recommendations Update OpenStack Glance to a version later than 32.0.0. Restrict access to the '/v2/tasks' API endpoint to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77648

Affected Products

Openstack Glance