Bug 2520853 (CVE-2026-77648) - CVE-2026-77648 glance: OpenStack Glance: Server-Side Request Forgery allows internal URL access by administrators
Summary: CVE-2026-77648 glance: OpenStack Glance: Server-Side Request Forgery allows i...
Keywords:
Status: NEW
Alias: CVE-2026-77648
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-20 22:57 UTC by OSIDB Bzimport
Modified: 2026-08-21 03:00 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-20 22:57:29 UTC
In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that
bypass import_filtering_opts, allowing an admin to fetch internal
URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.


Note You need to log in before you can comment on or make changes to this bug.