glance has 10 CVEs on record between 2015 and 2026. The median CVSS is 4.7 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.7
- Publish → KEV
- —
- Last 90 days
- 0 prev 1
Products
- glance 10
Worst active — by depth score
CVE-2026-34881Medium· 5.0OpenStack Glance is affected by Server-Side Request Forgery (SSRF)28CVE-2015-5286MediumOpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service28CVE-2015-5251MediumOpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions28CVE-2014-9623MediumOpenStack Glance Bypass the storage quota and Denial of service 28CVE-2014-5356MediumOpenStack Glance improper validation of the image_size_cap configuration option28
glance vulnerabilities
CVEs affecting glance, newest first. Open any entry for full detail, references, and exploit status.
10 CVEsRSS
CVE-2026-34881Medium· 5.0OpenStack Glance is affected by Server-Side Request Forgery (SSRF)
OpenStack Glance is affected by Server-Side Request Forgery (SSRF)
CVE-2014-0162MediumOpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
CVE-2015-5251MediumOpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions
OpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions
CVE-2014-9623MediumOpenStack Glance Bypass the storage quota and Denial of service
OpenStack Glance Bypass the storage quota and Denial of service
CVE-2015-5286MediumOpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service
OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service
CVE-2016-0757Medium· 4.3OpenStack Image Service (Glance) vulnerable to Improper Access Control
OpenStack Image Service (Glance) vulnerable to Improper Access Control
CVE-2014-5356MediumOpenStack Glance improper validation of the image_size_cap configuration option
OpenStack Glance improper validation of the image_size_cap configuration option
CVE-2015-1195MediumOpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme
OpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme
CVE-2015-1881NoneOpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authe…
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images …
CVE-2014-9684NoneOpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authe…
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images …