CVE-2026-77648: SSRF

Published Aug 20, 2026
·
Updated

In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass importfilteringopts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.

Affected Software

1 affected component
Openstack Glance><=32.0.0

Event History

Aug 20, 2026
CVE Published
via MITRE·10:37 PM
Data Sourced
via MITRE·10:37 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Exploitation requires an authenticated Glance administrator. The affected /v2/tasks API has been restricted to admins since the Xena release, limiting exposure to environments where admin credentials or access have been compromised.

2

What does an attacker need to do to trigger the issue?

The attacker must create a type=import task through the /v2/tasks API and provide an http:// or https:// URL. This can cause the Glance service to fetch a URL reachable from its own network, bypassing import_filtering_opts.

3

Are non-admin users affected by the vulnerable API?

The provided information states that the API has been available only to administrators since Xena. It does not indicate that non-admin users can directly invoke the affected task-import functionality.

4

What mitigation is available if patching cannot happen immediately?

Restrict access to Glance administrator credentials and the /v2/tasks API, especially task creation for type=import. Since the issue relies on Glance reaching internal HTTP or HTTPS endpoints, limiting the Glance service's network access can also reduce exposure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203