CVE-2026-77648
EUVD-2026-6375920.08.2026, 23:16
In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| openstack | glance | 30.0.0 ≤ 𝑥 < 30.3.0 | CNA |
| openstack | glance | 31.0.0 ≤ 𝑥 < 31.1.1 | CNA |
| openstack | glance | 32.0.0 | CNA |
Debian Releases