API Validation Flaw in OpenStack Glance Affects Image Management
CVE-2026-71198
7HIGH
What is CVE-2026-71198?
The location API in OpenStack Glance prior to version 32.0.1 is vulnerable due to insufficient validation of destination hosts when adding an HTTP location to images. The design flaw allows authenticated users to include internal endpoints, such as the cloud metadata service (169.254.169.254), when adding an image location. This exploitation can lead to unauthorized access to sensitive internal data through the image retrieval process. Both the new POST /v2/images/{id}/locations API and the legacy PATCH API with show_multiple_locations enabled are impacted, especially in deployments utilizing the HTTP store backend.
Affected Version(s)
Glance 16.0.0 < 30.2.1
Glance 31.0.0 < 31.1.1
Glance 32.0.0 < 32.0.1
