CVE-2026-51772: SSRF
Published Sep 25, 2026
·Updated
A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance. When the showmultiplelocations configuration option is enabled in glance-api.conf, an authenticated attacker can manipulate the locations attribute of an image in the queued state by sending a crafted HTTP PATCH request
Affected Software
1 affected component
Openstack Glance
Event History
Sep 25, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which deployments are exposed to this issue?
OpenStack Glance deployments using Image API v2 are exposed when the show_multiple_locations option is enabled in glance-api.conf.
2
What access and image state does an attacker need?
An attacker must be authenticated and able to send a crafted HTTP PATCH request that manipulates the locations attribute of an image in the queued state.