In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that
bypass import_filtering_opts, allowing an admin to fetch internal
URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 21 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Glance Admin Import Task SSRF

Thu, 20 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.
First Time appeared Openstack
Openstack glance
Weaknesses CWE-918
CPEs cpe:2.3:a:openstack:glance:*:*:*:*:*:*:*:*
Vendors & Products Openstack
Openstack glance
References
Metrics cvssV3_1

{'score': 2.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-20T22:37:31.431Z

Reserved: 2026-08-20T22:37:31.072Z

Link: CVE-2026-77648

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-20T23:16:28.797

Modified: 2026-08-20T23:16:28.797

Link: CVE-2026-77648

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T23:45:03Z

Weaknesses