CVE-2026-34881: SSRF

Published Feb 17, 2026
·
Updated

OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovfprocess image import plugin.

Other sources

Server-Side Request Forgery (SSRF) vulnerability in the web-download import workflow of OpenStack Glance. The issue arises because validateimporturi() validates only the initial URI using string-based hostname comparison, and urllib.request.urlopen() automatically follows HTTP redirects without revalidating the redirect destination. Additionally, alternative IP encodings (decimal, hexadecimal, octal representations) are not normalized prior to blacklist checks, allowing encoded internal IP addresses (e.g., 0x7f000001 for 127.0.0.1) to bypass validation. An authenticated user can supply a crafted URI that either redirects to an internal resource or directly references an encoded internal IP address, resulting in unauthorized internal network access and potential sensitive data exfiltration.

Red Hat

Affected Software

4 affected components
Openstack Glance<29.1.1, >=30.0.0<30.1.1, =31.0.0
Openstack Glance<29.1.1
Openstack Glance>=30.0.0<30.1.1
Openstack Glance=31.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenStack Glance to a version that resolves this vulnerability.

    Fixed in 29.1.1
  2. Upgrade

    Upgrade OpenStack Glance to a version that resolves this vulnerability.

    Fixed in 30.1.1
  3. Upgrade

    Upgrade OpenStack Glance to a version that resolves this vulnerability.

    Fixed in 31.0.0
  4. Configuration

    Ensure the optional ovf_process image import plugin is not enabled unless required, since it is listed as subject to the SSRF issue.

    OpenStack Glance (ovf_process image import plugin) ovf_process plugin enablement = not enabled by default
  5. Compensating control

    Restrict internal network egress/access from the Glance service (e.g., firewall/ACL) so SSRF attempts cannot reach internal services or metadata endpoints.

Event History

Feb 17, 2026
Data Sourced
via Red Hat·02:05 PM
DescriptionSeverityAffected Software
Mar 31, 2026
CVE Published
via MITRE·05:29 AM
Data Sourced
via MITRE·05:29 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-34881?

CVE-2026-34881 is classified as a high severity vulnerability due to the potential for Server-Side Request Forgery (SSRF) attacks.

2

How do I fix CVE-2026-34881?

To fix CVE-2026-34881, upgrade OpenStack Glance to versions 29.1.2, 30.1.1, or above 31.0.0.

3

What versions of OpenStack Glance are affected by CVE-2026-34881?

OpenStack Glance versions less than 29.1.1, between 30.0.0 and 30.1.1, and exactly 31.0.0 are affected by CVE-2026-34881.

4

What type of vulnerability is CVE-2026-34881?

CVE-2026-34881 is a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated users to bypass URL validation checks.

5

Which functionality in OpenStack Glance does CVE-2026-34881 impact?

CVE-2026-34881 specifically impacts the image import functionality within OpenStack Glance.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203