Server-Side Request Forgery in OpenStack Glance Image API
CVE-2026-51772
6.5MEDIUM
What is CVE-2026-51772?
In OpenStack Glance's Image API version 2, a critical Server-Side Request Forgery (SSRF) vulnerability has been identified. When the show_multiple_locations setting is activated in the glance-api.conf file, an authenticated user has the potential to exploit this vulnerability by crafting a malicious HTTP PATCH request. This request can manipulate the image location attributes of images that are currently queued, potentially leading to unauthorized access or information disclosure.
