Executive brief
OpenStack Glance, the image service for the OpenStack cloud platform, is affected by a security flaw in its image import functionality. An authenticated user can bypass security checks to force the server to make requests to internal network services that should be inaccessible. This could allow an attacker to probe internal infrastructure or access sensitive data within the private corporate network.
Technical details
OpenStack Glance is vulnerable to Server-Side Request Forgery (SSRF) within the 'web-download', 'glance-download', and 'ovf_process' image import methods. The vulnerability stems from three primary issues: the failure of 'urllib.request.urlopen()' to re-validate destinations after HTTP redirects, a lack of IP address normalization (allowing bypasses via hex, octal, or decimal encodings), and a total lack of URI validation in the optional OVF processing plugin. An authenticated attacker can provide a crafted URL that passes initial validation but redirects to internal services or uses encoded IP formats to bypass blacklists. This allows unauthorized access to internal network resources and potential data exfiltration. Patches are available in Glance versions 29.1.1, 30.1.1, and 32.0.0.0rc2.
Affected products
- OpenStack Glance < 29.1.1, 30.x < 30.1.1, 31.0.0
- Red Hat Red Hat OpenStack Platform 16.2, 17.1, 18.0
Timeline
- 2026-02-16: other: CVE request filed with MITRE
- 2026-03-19: advisory: Original OSSA-2026-004 advisory published
- 2026-03-31: disclosed: CVE-2026-34881 assigned and published