VulnSea

glance vulnerabilities

CVEs whose affected-version data names the glance package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

15 CVEsRSS

CVE-2026-71198High· 7.0
1w ago

In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image

In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply the imp…

TwilightOpenStack · GlanceEPSS 0.45%via NVD
CVE-2026-34881Medium· 5.0
5mo ago

OpenStack Glance is affected by Server-Side Request Forgery (SSRF)

OpenStack Glance is affected by Server-Side Request Forgery (SSRF)

Sunlitglance · glanceEPSS 0.27%via OSV
CVE-2024-32498Medium· 6.5
2y ago

OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access

OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access

Sunlitcinder · cinderEPSS 0.83%via OSV
CVE-2022-47951Medium· 5.7
3y ago

OpenStack Cinder, glance, and Nova vulnerable to Path Traversal

OpenStack Cinder, glance, and Nova vulnerable to Path Traversal

Sunlitcinder · cinderEPSS 1.0%via OSV
CVE-2014-0162Medium
4y ago

OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability

OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability

Sunlitglance · glanceEPSS 2.0%via OSV
CVE-2015-5251Medium
4y ago

OpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions

OpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions

Sunlitglance · glanceEPSS 2.1%via OSV
CVE-2014-9623Medium
4y ago

OpenStack Glance Bypass the storage quota and Denial of service

OpenStack Glance Bypass the storage quota and Denial of service

Sunlitglance · glanceEPSS 2.9%via OSV
CVE-2015-5286Medium
4y ago

OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service

OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service

Sunlitglance · glanceEPSS 2.4%via OSV
CVE-2016-0757Medium· 4.3
4y ago

OpenStack Image Service (Glance) vulnerable to Improper Access Control

OpenStack Image Service (Glance) vulnerable to Improper Access Control

Sunlitglance · glanceEPSS 1.7%via OSV
CVE-2014-5356Medium
4y ago

OpenStack Glance improper validation of the image_size_cap configuration option

OpenStack Glance improper validation of the image_size_cap configuration option

Sunlitglance · glanceEPSS 2.1%via OSV
CVE-2015-1195Medium
4y ago

OpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme

OpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme

Sunlitglance · glanceEPSS 2.8%via OSV
CVE-2015-5162High· 7.5
4y ago

OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption

OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption

Twilightcinder · cinderEPSS 2.9%via OSV
CVE-2017-7200Medium· 5.8
9y ago

An SSRF issue was discovered in OpenStack Glance before Newton

An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'ht…

Sunlitopenstack · glanceEPSS 2.1%via NVD
CVE-2015-1881None
11y ago

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authe…

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images …

Sunlitglance · glanceEPSS 2.1%via OSV
CVE-2014-9684None
11y ago

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authe…

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images …

Sunlitglance · glanceEPSS 2.0%via OSV
glance vulnerabilities (CVEs) · VulnSea