Server-Side Request Forgery in OpenStack Glance by OpenStack
CVE-2026-34881

5MEDIUM

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34881?

OpenStack Glance versions prior to 29.1.1 and between 30.0.0 and 30.1.1, as well as version 31.0.0, are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. This issue permits authenticated users to exploit HTTP redirects, thereby circumventing URL validation checks and gaining access to internal services. The vulnerability primarily affects the image import functionality, specifically through the web-download and glance-download import methods, along with the optional ovf_process image import plugin, which is not enabled by default.

Affected Version(s)

Glance 0 < 29.1.1

Glance 30.0.0 < 30.1.1

Glance 31.0.0

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.