API Validation Flaw in OpenStack Glance Affects Image Management
CVE-2026-71198

7HIGH

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-71198?

The location API in OpenStack Glance prior to version 32.0.1 is vulnerable due to insufficient validation of destination hosts when adding an HTTP location to images. The design flaw allows authenticated users to include internal endpoints, such as the cloud metadata service (169.254.169.254), when adding an image location. This exploitation can lead to unauthorized access to sensitive internal data through the image retrieval process. Both the new POST /v2/images/{id}/locations API and the legacy PATCH API with show_multiple_locations enabled are impacted, especially in deployments utilizing the HTTP store backend.

Affected Version(s)

Glance 16.0.0 < 30.2.1

Glance 31.0.0 < 31.1.1

Glance 32.0.0 < 32.0.1

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.