PYSEC-2026-2492

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/glance/PYSEC-2026-2492.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2026-2492
Aliases
Published
2026-07-13T14:36:46.009576Z
Modified
2026-07-13T16:49:09.501090610Z
Severity
  • 5.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N CVSS Calculator
Summary
OpenStack Glance is affected by Server-Side Request Forgery (SSRF)
Details

OpenStack Glance versions < 29.1.1, >= 30.0.0 < 30.1.1, == 31.0.0 are affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only the glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.

References

Affected packages

PyPI / glance

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
29.2.0
Introduced
30.0.0
Fixed
30.2.0
Introduced
31.0.0
Fixed
31.1.0

Affected versions

15.*
15.0.2
17.*
17.0.1
18.*
18.0.0.0b1
18.0.0.0rc1
18.0.0
18.0.1
19.*
19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
20.*
20.0.0.0b1
20.0.0.0b2
20.0.0.0b3
20.0.0.0rc1
20.0.0.0rc2
20.0.0
20.0.1
20.1.0
20.2.0
21.*
21.0.0.0b1
21.0.0.0b2
21.0.0.0rc1
21.0.0.0rc2
21.0.0
21.1.0
22.*
22.0.0.0b2
22.0.0.0b3
22.0.0.0rc1
22.0.0
22.1.0
22.1.1
23.*
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.0.0
23.1.0
24.*
24.0.0.0rc1
24.0.0
24.1.0
24.2.0
24.2.1
25.*
25.0.0.0b2
25.0.0.0b3
25.0.0.0rc1
25.0.0
25.1.0
26.*
26.0.0.0b2
26.0.0.0b3
26.0.0.0rc1
26.0.0
26.1.0
27.*
27.0.0.0b1
27.0.0.0b2
27.0.0.0rc1
27.0.0
27.1.0
27.1.1
28.*
28.0.0.0b2
28.0.0.0rc1
28.0.0
28.0.1
28.1.0
28.2.0
29.*
29.0.0.0b1
29.0.0.0b2
29.0.0.0b3
29.0.0.0rc1
29.0.0
29.1.0
30.*
30.0.0
30.1.0
31.*
31.0.0

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/glance/PYSEC-2026-2492.yaml"