CVE-2026-77648

⚪ Do wiadomości

Błąd SSRF w OpenStack Glance pozwala administratorom na dostęp do wewnętrznych URLi.

CVSS
2.2
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.

ssrf Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS2.2
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-08-20 23:16:28 UTC
Ostatnia modyfikacja (NVD)2026-08-24 16:17:23 UTC
Referencje