---
id: CVE-2026-51772
title: >-
  A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API
  (v2) of OpenStack Glance
summary: >-
  A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API
  (v2) of OpenStack Glance. When the show_multiple_locations configuration
  option is enabled in glance-api.conf, an authenticated attacker can manipulate
  the locati…
severity: none
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T13:17:14.550'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-51772'
references:
  - url: 'https://github.com/sadandbset/CVE-2026-51772-CVE-2026-51773'
    label: cve@mitre.org
tags:
  - nvd
  - exploit-available
  - cve.org
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/sadandbset/CVE-2026-51772-CVE-2026-51773'
  checkedAt: '2026-09-25T14:10:20.849Z'
exploitAvailable: true
ingestedAt: '2026-09-25T13:08:53.488Z'
---

## Overview

A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance. When the show_multiple_locations configuration option is enabled in glance-api.conf, an authenticated attacker can manipulate the locations attribute of an image in the queued state by sending a crafted HTTP PATCH request

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
