---
id: CVE-2026-77648
title: >-
  In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import
  tasks that

  bypass import_filtering_opts, allowing an admin to fetch internal

  URLs from the Glance service network (aka SSRF), as long as https:// or
  http:// is use…
summary: >-
  In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import
  tasks that

  bypass import_filtering_opts, allowing an admin to fetch internal

  URLs from the Glance service network (aka SSRF), as long as https:// or
  http:// is use…
severity: low
cvss: 2.2
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-918
published: '2026-08-20'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T16:03:22.897'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77648'
references:
  - url: 'https://wiki.openstack.org/wiki/OSSN/OSSN-0105'
    label: cve@mitre.org
  - url: 'https://www.openwall.com/lists/oss-security/2026/08/11/7'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00295
epssPercentile: 0.19719
ingestedAt: '2026-09-09T16:14:05.514Z'
---

## Overview

In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that
bypass import_filtering_opts, allowing an admin to fetch internal
URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
