CVE-2026-77648

EUVD-2026-63759
In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that
bypass import_filtering_opts, allowing an admin to fetch internal
URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
mitreCNA
2.2 LOW
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 9.15%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
openstackglance
30.0.0 ≤
𝑥
< 30.3.0
CNA
openstackglance
31.0.0 ≤
𝑥
< 31.1.1
CNA
openstackglance
32.0.0
CNA
Debian logo
Debian Releases
Debian Product
Codename
glance
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
2:32.0.0-3
fixed
sid
2:32.0.0-3
fixed
trixie
no-dsa