---
id: CVE-2014-9684
aliases:
  - PYSEC-2015-37
  - GHSA-h737-q6g6-8wr6
title: >-
  OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2
  does not properly remove images, which allows remote authe…
summary: >-
  OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2
  does not properly remove images, which allows remote authenticated users to
  cause a denial of service (disk consumption) by creating a large number of
  images …
severity: none
vendor: glance
product: glance
ecosystem: pip
affected:
  - glance < 11.0.0a0
patched:
  - glance 11.0.0a0
published: '2015-02-24'
updated: '2026-07-02'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2015-37'
references:
  - url: >-
      http://lists.openstack.org/pipermail/openstack-announce/2015-February/000336.html
  - url: 'https://bugs.launchpad.net/glance/+bug/1371118'
  - url: 'http://rhn.redhat.com/errata/RHSA-2015-0938.html'
  - url: 'http://www.securityfocus.com/bid/72692'
  - url: 'https://github.com/advisories/GHSA-h737-q6g6-8wr6'
tags:
  - osv
  - pip
epss: 0.01997
epssPercentile: 0.79599
ingestedAt: '2026-07-08T18:25:55.322Z'
---

## Overview

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them before the uploads finish, a different vulnerability than CVE-2015-1881.

## Affected packages

- `glance < 11.0.0a0`

## Remediation

Upgrade to a patched release:

- `glance 11.0.0a0`
