bypass import_filtering_opts, allowing an admin to fetch internal
URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 24 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Aug 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Glance Admin Import Task SSRF | glance: OpenStack Glance: Server-Side Request Forgery allows internal URL access by administrators |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 21 Aug 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Glance Admin Import Task SSRF |
Thu, 20 Aug 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases. | |
| First Time appeared |
Openstack
Openstack glance |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:openstack:glance:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack glance |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-24T16:00:10.928Z
Reserved: 2026-08-20T22:37:31.072Z
Link: CVE-2026-77648
Updated: 2026-08-24T15:59:59.547Z
Status : Awaiting Analysis
Published: 2026-08-20T23:16:28.797
Modified: 2026-09-09T16:03:22.897
Link: CVE-2026-77648
OpenCVE Enrichment
Updated: 2026-08-20T23:45:03Z