{"id":"CVE-2026-51773","title":"An issue in the VMware datastore driver of OpenStack glance_store","summary":"An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destina…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-918","CWE-201"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T17:17:08.900","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-51773","references":[{"url":"https://github.com/sadandbset/CVE-2026-51772-CVE-2026-51773","label":"cve@mitre.org"},{"url":"https://github.com/sadandbset/CVE-2026-51772-CVE-2026-51773/blob/main/CVE-2026-51773.md","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-51773.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-51773"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2541405"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-51773"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-51773"}],"tags":["nvd","cve.org","exploit-available","csaf","vex","red-hat"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-09-25T16:23:29.856212Z"},"ingestedAt":"2026-09-25T13:08:53.486Z","vendor":"Red Hat","product":"Red Hat OpenStack Platform 16.2","affected":["openstack_platform_13_queens","openstack_platform 16.2","openstack_platform 17.1","openstack_platform 18.0"],"scores":{"nvd":8.1,"vendor":6.5},"slug":"CVE-2026-51773","body":"## Overview\n\nAn issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destination host before attaching sensitive authentication headers.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0 · no fix planned: Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0 · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-51773.json)","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":44.6,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":211084,"id":"CVE-2026-51773","ts":1790356445797,"field":"exploit_available","old":"false","new":"true"},{"seq":211083,"id":"CVE-2026-51773","ts":1790356445797,"field":"cvss","old":null,"new":"8.1"},{"seq":211082,"id":"CVE-2026-51773","ts":1790356445797,"field":"severity","old":"none","new":"high"}]}