Fedora Account System
Red Hat Associate
Red Hat Customer
Server-Side Request Forgery (SSRF) vulnerability in the OVF processing component of OpenStack Glance. The flaw is caused by direct invocation of urllib.request.urlopen(uri) in the _get_ova_iter_objects() function without any URI validation, redirect validation, or IP normalization. An authenticated administrator can supply a malicious URI (including redirects to internal services such as 127.0.0.1 or metadata endpoints), which the Glance service fetches and processes as an OVF package. This allows attackers to access internal services, exfiltrate sensitive data, and potentially compromise the cloud control plane. Exploitation requires administrative privileges but can be performed remotely without user interaction.
This issue has been addressed in the following products: Red Hat OpenStack Services on OpenShift 18.0 Via RHSA-2026:39812 https://access.redhat.com/errata/RHSA-2026:39812