Glance vulnerabilities
CVEs whose affected-version data names the Glance package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
15 CVEsRSS
CVE-2026-71198High· 7.0In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image
In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply the imp…
CVE-2026-34881Medium· 5.0OpenStack Glance is affected by Server-Side Request Forgery (SSRF)
OpenStack Glance is affected by Server-Side Request Forgery (SSRF)
CVE-2024-32498Medium· 6.5OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
CVE-2022-47951Medium· 5.7OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
CVE-2014-0162MediumOpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
CVE-2015-5251MediumOpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions
OpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions
CVE-2014-9623MediumOpenStack Glance Bypass the storage quota and Denial of service
OpenStack Glance Bypass the storage quota and Denial of service
CVE-2015-5286MediumOpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service
OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service
CVE-2016-0757Medium· 4.3OpenStack Image Service (Glance) vulnerable to Improper Access Control
OpenStack Image Service (Glance) vulnerable to Improper Access Control
CVE-2014-5356MediumOpenStack Glance improper validation of the image_size_cap configuration option
OpenStack Glance improper validation of the image_size_cap configuration option
CVE-2015-1195MediumOpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme
OpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme
CVE-2015-5162High· 7.5OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption
OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption
CVE-2017-7200Medium· 5.8An SSRF issue was discovered in OpenStack Glance before Newton
An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'ht…
CVE-2015-1881NoneOpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authe…
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images …
CVE-2014-9684NoneOpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authe…
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images …