CVE-2026-77648 - OpenStack Glance Server-Side Request Forgery
CVE ID :CVE-2026-77648
Published : Aug. 20, 2026, 11:16 p.m. | 2 hours, 45 minutes ago
Description :In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.
Severity: 2.2 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 20, 2026, 11:16 p.m. | 2 hours, 45 minutes ago
Description :In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.
Severity: 2.2 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...