CVE-2026-51772
- EPSS 0.31%
- Veröffentlicht 25.09.2026 00:00:00
- Zuletzt bearbeitet 30.09.2026 17:23:08
A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance. When the show_multiple_locations configuration option is enabled in glance-api.conf, an authenticated attacker can manipulate the locations attribute...
- EPSS 0.45%
- Veröffentlicht 14.09.2026 07:17:16
- Zuletzt bearbeitet 22.09.2026 19:56:19
In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply the import_filtering...
CVE-2026-77648
- EPSS -
- Veröffentlicht 20.08.2026 22:37:31
- Zuletzt bearbeitet 09.09.2026 16:03:22
In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API h...
CVE-2026-34881
- EPSS 0.27%
- Veröffentlicht 31.03.2026 05:29:08
- Zuletzt bearbeitet 14.08.2026 13:18:15
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image im...
CVE-2024-32498
- EPSS 0.84%
- Veröffentlicht 05.07.2024 02:15:09
- Zuletzt bearbeitet 04.11.2025 17:15:52
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an...
CVE-2022-4134
- EPSS 0.32%
- Veröffentlicht 06.03.2023 23:15:11
- Zuletzt bearbeitet 06.03.2025 20:15:37
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
CVE-2022-47951
- EPSS 1.03%
- Veröffentlicht 26.01.2023 22:15:25
- Zuletzt bearbeitet 31.03.2025 17:15:39
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image ...
CVE-2016-8611
- EPSS 2.33%
- Veröffentlicht 31.07.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 02:59:40
A vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2 `/images` API POST method for authenticated users, resulting in possible denial of service attacks through database table saturat...
CVE-2015-8234
- EPSS 1.21%
- Veröffentlicht 29.03.2017 14:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.
CVE-2017-7200
- EPSS 2.03%
- Veröffentlicht 21.03.2017 06:59:00
- Zuletzt bearbeitet 17.09.2026 13:59:34
An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'http://localhos...