CVE-2026-51773: Pypi/glance_store vulnerability
Published Sep 25, 2026
·Updated
An issue in the VMware datastore driver of OpenStack glancestore. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the retryrequest function fails to validate the destination host before attaching sensitive authentication headers.
Affected Software
1 affected component
pypi/glance_store
Event History
Sep 25, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which deployments are exposed?
Deployments using the VMware datastore driver in glance_store are affected by this issue.
2
What does an attacker need to exploit this?
The attacker must be authenticated and able to supply a malicious image location URI that points to an external server.
3
What could be exposed if exploitation succeeds?
Sensitive authentication headers may be sent to the attacker-controlled external destination.