---
id: CVE-2015-1881
aliases:
  - PYSEC-2015-38
  - GHSA-4jp4-3c62-r8jv
title: >-
  OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2
  does not properly remove images, which allows remote authe…
summary: >-
  OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2
  does not properly remove images, which allows remote authenticated users to
  cause a denial of service (disk consumption) by creating a large number of
  images …
severity: none
vendor: glance
product: glance
ecosystem: pip
affected:
  - glance < 11.0.0a0
patched:
  - glance 11.0.0a0
published: '2015-02-24'
updated: '2026-07-02'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2015-38'
references:
  - url: 'https://bugs.launchpad.net/glance/+bug/1420696'
  - url: >-
      http://lists.openstack.org/pipermail/openstack-announce/2015-February/000336.html
  - url: 'http://rhn.redhat.com/errata/RHSA-2015-0938.html'
  - url: 'http://www.securityfocus.com/bid/72694'
  - url: 'https://github.com/advisories/GHSA-4jp4-3c62-r8jv'
tags:
  - osv
  - pip
epss: 0.02118
epssPercentile: 0.81054
ingestedAt: '2026-07-08T18:25:55.324Z'
---

## Overview

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than CVE-2014-9684.

## Affected packages

- `glance < 11.0.0a0`

## Remediation

Upgrade to a patched release:

- `glance 11.0.0a0`
