CVE-2026-34881Medium· 5.0▾ SunlitOpenStack Glance is affected by Server-Side Request Forgery (SSRF)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
0.3% → 0.4%
OpenStack Glance versions < 29.1.1, >= 30.0.0 < 30.1.1, == 31.0.0 are affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only the glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.
glance < 29.2.0glance >= 30.0.0, < 30.2.0glance >= 31.0.0, < 31.1.0Upgrade to a patched release:
glance 29.2.0glance 30.2.0glance 31.1.0Connected by shared product, vendor, weakness, or advisory.
CVE-2015-1195MediumOpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme
CVE-2017-7200Medium· 5.8An SSRF issue was discovered in OpenStack Glance before Newton
CVE-2014-9623MediumOpenStack Glance Bypass the storage quota and Denial of service
CVE-2014-5356MediumOpenStack Glance improper validation of the image_size_cap configuration option
CVE-2015-1881NoneOpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authe…
CVE-2014-9684NoneOpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authe…