CVE-2026-77648
2.2
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Summary
In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenStack | Glance | 30.0.0 < 30.3.0 | affected |
| OpenStack | Glance | 31.0.0 < 31.1.1 | affected |
| OpenStack | Glance | 32.0.0 | affected |
Weaknesses
- CWE-918: CWE-918 Server-Side Request Forgery (SSRF)
References
- https://wiki.openstack.org/wiki/OSSN/OSSN-0105
- https://www.openwall.com/lists/oss-security/2026/08/11/7
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.