REDHAT-BUG-2440368: SSRF

Published Feb 17, 2026
·
Updated

Server-Side Request Forgery (SSRF) vulnerability in the web-download import workflow of OpenStack Glance. The issue arises because validateimporturi() validates only the initial URI using string-based hostname comparison, and urllib.request.urlopen() automatically follows HTTP redirects without revalidating the redirect destination. Additionally, alternative IP encodings (decimal, hexadecimal, octal representations) are not normalized prior to blacklist checks, allowing encoded internal IP addresses (e.g., 0x7f000001 for 127.0.0.1) to bypass validation. An authenticated user can supply a crafted URI that either redirects to an internal resource or directly references an encoded internal IP address, resulting in unauthorized internal network access and potential sensitive data exfiltration.

Affected Software

1 affected component
Openstack Glance

Event History

Feb 17, 2026
Data Sourced
via Red Hat·02:05 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2440368?

The severity of REDHAT-BUG-2440368 is classified as high with a score of 7.

2

What is the nature of the vulnerability in REDHAT-BUG-2440368?

REDHAT-BUG-2440368 is a Server-Side Request Forgery (SSRF) vulnerability in the web-download import workflow of OpenStack Glance.

3

How does the vulnerability in REDHAT-BUG-2440368 occur?

The vulnerability occurs because validate_import_uri() only validates the initial URI and does not properly handle HTTP redirects.

4

How can I mitigate the issue of REDHAT-BUG-2440368?

To mitigate REDHAT-BUG-2440368, ensure that additional validation is implemented for all URIs being imported, especially after following redirects.

5

Is REDHAT-BUG-2440368 present in all versions of OpenStack Glance?

The specific details regarding affected versions of OpenStack Glance related to REDHAT-BUG-2440368 should be checked in the official security advisories.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203