Server-Side Request Forgery Vulnerability in OpenStack Glance
CVE-2026-77648

2.2LOW

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-77648?

In OpenStack Glance version 32.0.0, a vulnerability exists in the /v2/tasks API, which allows an administrator to bypass import filtering options for type=import tasks. This flaw can lead to fetching internal URLs from the Glance service network using either HTTP or HTTPS protocols, exposing sensitive internal data. The API accessibility to admins only since the release of Xena, along with its deprecation over several releases, highlights the criticality of addressing this vulnerability to safeguard the platform.

Affected Version(s)

Glance 30.0.0 < 30.3.0

Glance 31.0.0 < 31.1.1

Glance 32.0.0

References

CVSS V3.1

Score:
2.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.