https://seclists.org/oss-sec/2026/q1/347: [OSSA-2026-004] Glance: Server-Side quest Forgery (SSRF) vulnerabilities in OpenStack Glance image import functionality (CVE-2026-pending)
Published Mar 19, 2026
·Updated
Affected Software
1 affected component
Openstack Glance<29.1.1, >=30.0.0<30.1.1, =31.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-pending?
CVE-2026-pending is considered to be a high-severity vulnerability due to its potential for exploitation.
2
How do I fix CVE-2026-pending?
To mitigate CVE-2026-pending, ensure that your OpenStack Glance is updated to the latest version with the security patch applied.
3
What kind of attack does CVE-2026-pending enable?
CVE-2026-pending allows attackers to perform Server-Side Request Forgery (SSRF), potentially leading to unauthorized access to internal resources.
4
Which versions of OpenStack Glance are affected by CVE-2026-pending?
CVE-2026-pending affects specific versions of OpenStack Glance prior to the release that fixes the SSRF vulnerability.
5
Is there a workaround for CVE-2026-pending?
Currently, the recommended action is to apply the security patch; specific workarounds for CVE-2026-pending may not be effective.