{"schema_version":1,"title":"glance (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 22 vulnerabilities in glance (PyPI): 0 in the last 7 days and 11 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2024-32498, was published on 13 July 2026.","url":"https://junglewise.ai/threats/technologies/pypi-glance","json_url":"https://junglewise.ai/threats/technologies/pypi-glance.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pypi-glance","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":22,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":11,"last_365_days":12},"latest":[{"cve":"CVE-2024-32498","cvss":3.1,"epss":0.0084,"slug":"cve-2024-32498-openstack-cinder-glance-and-nova-vulnerable-to-arbitrary-file","title":"PYSEC-2026-2493 - OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access","severity":"low","exploited":false,"published_at":"2026-07-13T14:36:32.3204+00:00","url":"https://junglewise.ai/threats/cve-2024-32498-openstack-cinder-glance-and-nova-vulnerable-to-arbitrary-file"},{"cve":"CVE-2022-47951","cvss":3.1,"epss":0.0103,"slug":"cve-2022-47951-openstack-cinder-glance-and-nova-vulnerable-to-path-traversal","title":"PYSEC-2026-868 - OpenStack Cinder, glance, and Nova vulnerable to Path Traversal","severity":"low","exploited":false,"published_at":"2026-07-07T10:17:27.389246+00:00","url":"https://junglewise.ai/threats/cve-2022-47951-openstack-cinder-glance-and-nova-vulnerable-to-path-traversal"},{"cve":"CVE-2014-0162","epss":0.0199,"slug":"cve-2014-0162-openstack-image-registry-and-delivery-service-glance-improper","title":"PYSEC-2026-817 - OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:26.078363+00:00","url":"https://junglewise.ai/threats/cve-2014-0162-openstack-image-registry-and-delivery-service-glance-improper"},{"cve":"CVE-2015-5251","cvss":4,"epss":0.0205,"slug":"cve-2015-5251-openstack-image-service-glance-allows-remote-authenticated-users","title":"PYSEC-2026-816 - OpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions","severity":"medium","exploited":false,"published_at":"2026-07-06T08:03:25.683815+00:00","url":"https://junglewise.ai/threats/cve-2015-5251-openstack-image-service-glance-allows-remote-authenticated-users"},{"cve":"CVE-2015-5286","epss":0.024,"slug":"cve-2015-5286-openstack-image-service-glance-allows-remote-authenticated-users","title":"PYSEC-2026-812 - OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:25.587152+00:00","url":"https://junglewise.ai/threats/cve-2015-5286-openstack-image-service-glance-allows-remote-authenticated-users"},{"cve":"CVE-2016-0757","cvss":3,"epss":0.0148,"slug":"cve-2016-0757-openstack-image-service-glance-vulnerable-to-improper-access","title":"PYSEC-2026-811 - OpenStack Image Service (Glance) vulnerable to Improper Access Control","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:25.543728+00:00","url":"https://junglewise.ai/threats/cve-2016-0757-openstack-image-service-glance-vulnerable-to-improper-access"},{"cve":"CVE-2014-9623","epss":0.0287,"slug":"cve-2014-9623-openstack-glance-bypass-the-storage-quota-and-denial-of-service","title":"PYSEC-2026-813 - OpenStack Glance Bypass the storage quota and Denial of service","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:25.33725+00:00","url":"https://junglewise.ai/threats/cve-2014-9623-openstack-glance-bypass-the-storage-quota-and-denial-of-service"},{"cve":"CVE-2014-5356","epss":0.0215,"slug":"cve-2014-5356-openstack-glance-improper-validation-of-the-image-size-cap","title":"PYSEC-2026-810 - OpenStack Glance improper validation of the image_size_cap configuration option","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:25.231944+00:00","url":"https://junglewise.ai/threats/cve-2014-5356-openstack-glance-improper-validation-of-the-image-size-cap"},{"cve":"CVE-2017-7200","cvss":3,"epss":0.0206,"slug":"cve-2017-7200-openstack-glance-server-side-request-forgery-ssrf","title":"PYSEC-2026-814 - OpenStack Glance Server-Side Request Forgery (SSRF)","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:24.990051+00:00","url":"https://junglewise.ai/threats/cve-2017-7200-openstack-glance-server-side-request-forgery-ssrf"},{"cve":"CVE-2015-5162","cvss":3,"epss":0.0309,"slug":"cve-2015-5162-openstack-cinder-glance-and-nova-contain-uncontrolled-resource","title":"PYSEC-2026-871 - OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:24.240424+00:00","url":"https://junglewise.ai/threats/cve-2015-5162-openstack-cinder-glance-and-nova-contain-uncontrolled-resource"},{"cve":"CVE-2015-1195","epss":0.0279,"slug":"cve-2015-1195-openstack-glance-v2-api-unrestricted-path-traversal-through","title":"PYSEC-2026-815 - OpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:21.946037+00:00","url":"https://junglewise.ai/threats/cve-2015-1195-openstack-glance-v2-api-unrestricted-path-traversal-through"},{"cve":"CVE-2026-34881","cvss":5,"epss":0.0044,"slug":"cve-2026-34881-openstack-glance-ssrf-in-image-import-functionality","title":"OpenStack Glance SSRF in image import functionality","severity":"medium","exploited":false,"published_at":"2026-03-31T06:16:01.13+00:00","url":"https://junglewise.ai/threats/cve-2026-34881-openstack-glance-ssrf-in-image-import-functionality"},{"cve":"CVE-2022-4134","cvss":3.1,"epss":0.0033,"slug":"cve-2022-4134-openstack-glance-inclusion-of-functionality-from-untrusted-control","title":"PYSEC-2023-270 - A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integr","severity":"low","exploited":false,"published_at":"2023-03-06T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4134-openstack-glance-inclusion-of-functionality-from-untrusted-control"},{"cve":"CVE-2013-1840","cvss":3.5,"epss":0.0137,"slug":"cve-2013-1840-openstack-glance-credential-leak-in-v1-api-cached-image-requests","title":"OpenStack Glance credential leak in v1 API cached image requests","severity":"low","exploited":false,"published_at":"2022-05-17T01:36:25+00:00","url":"https://junglewise.ai/threats/cve-2013-1840-openstack-glance-credential-leak-in-v1-api-cached-image-requests"},{"cve":"CVE-2015-8234","cvss":3,"epss":0.0121,"slug":"cve-2015-8234-openstack-glance-signature-verification-bypass","title":"PYSEC-2017-143 - The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted","severity":"low","exploited":false,"published_at":"2017-03-29T14:59:00+00:00","url":"https://junglewise.ai/threats/cve-2015-8234-openstack-glance-signature-verification-bypass"},{"cve":"CVE-2015-5163","cvss":3.1,"epss":0.015,"slug":"cve-2015-5163-openstack-image-service-glance-allows-remote-authenticated-users","title":"PYSEC-2015-39 - The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticat","severity":"low","exploited":false,"published_at":"2015-08-19T15:59:00+00:00","url":"https://junglewise.ai/threats/cve-2015-5163-openstack-image-service-glance-allows-remote-authenticated-users"},{"cve":"CVE-2015-1881","cvss":3.1,"epss":0.0212,"slug":"cve-2015-1881-openstack-glance-denial-of-service-by-creating-a-large-number-of","title":"PYSEC-2015-38 - OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenti","severity":"low","exploited":false,"published_at":"2015-02-24T15:59:00+00:00","url":"https://junglewise.ai/threats/cve-2015-1881-openstack-glance-denial-of-service-by-creating-a-large-number-of"},{"cve":"CVE-2014-9684","cvss":3.1,"epss":0.02,"slug":"cve-2014-9684-openstack-glance-denial-of-service-by-creating-a-large-number-of","title":"PYSEC-2015-37 - OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenti","severity":"low","exploited":false,"published_at":"2015-02-24T15:59:00+00:00","url":"https://junglewise.ai/threats/cve-2014-9684-openstack-glance-denial-of-service-by-creating-a-large-number-of"},{"cve":"CVE-2014-1948","cvss":3.1,"epss":0.0031,"slug":"cve-2014-1948-openstack-glance-sensitive-information-disclosure-via-logs","title":"PYSEC-2014-102 - OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swif","severity":"low","exploited":false,"published_at":"2014-02-14T15:55:00+00:00","url":"https://junglewise.ai/threats/cve-2014-1948-openstack-glance-sensitive-information-disclosure-via-logs"},{"cve":"CVE-2013-0212","epss":0.0299,"slug":"cve-2013-0212-openstack-glance-logs-user-name-and-password-in-cleartext","title":"PYSEC-2013-37 - store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the","severity":"info","exploited":false,"published_at":"2013-02-24T21:55:00+00:00","url":"https://junglewise.ai/threats/cve-2013-0212-openstack-glance-logs-user-name-and-password-in-cleartext"},{"cve":"CVE-2012-5482","epss":0.0275,"slug":"cve-2012-5482-openstack-glance-arbitrary-deletion-of-non-protected-images","title":"PYSEC-2012-30 - The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protec","severity":"info","exploited":false,"published_at":"2012-11-11T13:00:00+00:00","url":"https://junglewise.ai/threats/cve-2012-5482-openstack-glance-arbitrary-deletion-of-non-protected-images"},{"cve":"CVE-2012-4573","epss":0.0335,"slug":"cve-2012-4573-openstack-glance-arbitrary-deletion-of-non-protected-images","title":"PYSEC-2012-29 - The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protec","severity":"info","exploited":false,"published_at":"2012-11-11T13:00:00+00:00","url":"https://junglewise.ai/threats/cve-2012-4573-openstack-glance-arbitrary-deletion-of-non-protected-images"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":10},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"glance (PyPI)","slug":"pypi-glance","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"description":"OpenStack image service for storing, managing, and retrieving virtual machine images.","url":"https://junglewise.ai/threats/technologies/pypi-glance"},"most_severe":[{"cve":"CVE-2026-34881","cvss":5,"epss":0.0044,"slug":"cve-2026-34881-openstack-glance-ssrf-in-image-import-functionality","title":"OpenStack Glance SSRF in image import functionality","severity":"medium","exploited":false,"published_at":"2026-03-31T06:16:01.13+00:00","url":"https://junglewise.ai/threats/cve-2026-34881-openstack-glance-ssrf-in-image-import-functionality"},{"cve":"CVE-2015-5251","cvss":4,"epss":0.0205,"slug":"cve-2015-5251-openstack-image-service-glance-allows-remote-authenticated-users","title":"PYSEC-2026-816 - OpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions","severity":"medium","exploited":false,"published_at":"2026-07-06T08:03:25.683815+00:00","url":"https://junglewise.ai/threats/cve-2015-5251-openstack-image-service-glance-allows-remote-authenticated-users"},{"cve":"CVE-2013-1840","cvss":3.5,"epss":0.0137,"slug":"cve-2013-1840-openstack-glance-credential-leak-in-v1-api-cached-image-requests","title":"OpenStack Glance credential leak in v1 API cached image requests","severity":"low","exploited":false,"published_at":"2022-05-17T01:36:25+00:00","url":"https://junglewise.ai/threats/cve-2013-1840-openstack-glance-credential-leak-in-v1-api-cached-image-requests"},{"cve":"CVE-2015-1881","cvss":3.1,"epss":0.0212,"slug":"cve-2015-1881-openstack-glance-denial-of-service-by-creating-a-large-number-of","title":"PYSEC-2015-38 - OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenti","severity":"low","exploited":false,"published_at":"2015-02-24T15:59:00+00:00","url":"https://junglewise.ai/threats/cve-2015-1881-openstack-glance-denial-of-service-by-creating-a-large-number-of"},{"cve":"CVE-2014-9684","cvss":3.1,"epss":0.02,"slug":"cve-2014-9684-openstack-glance-denial-of-service-by-creating-a-large-number-of","title":"PYSEC-2015-37 - OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenti","severity":"low","exploited":false,"published_at":"2015-02-24T15:59:00+00:00","url":"https://junglewise.ai/threats/cve-2014-9684-openstack-glance-denial-of-service-by-creating-a-large-number-of"},{"cve":"CVE-2015-5163","cvss":3.1,"epss":0.015,"slug":"cve-2015-5163-openstack-image-service-glance-allows-remote-authenticated-users","title":"PYSEC-2015-39 - The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticat","severity":"low","exploited":false,"published_at":"2015-08-19T15:59:00+00:00","url":"https://junglewise.ai/threats/cve-2015-5163-openstack-image-service-glance-allows-remote-authenticated-users"},{"cve":"CVE-2022-47951","cvss":3.1,"epss":0.0103,"slug":"cve-2022-47951-openstack-cinder-glance-and-nova-vulnerable-to-path-traversal","title":"PYSEC-2026-868 - OpenStack Cinder, glance, and Nova vulnerable to Path Traversal","severity":"low","exploited":false,"published_at":"2026-07-07T10:17:27.389246+00:00","url":"https://junglewise.ai/threats/cve-2022-47951-openstack-cinder-glance-and-nova-vulnerable-to-path-traversal"},{"cve":"CVE-2024-32498","cvss":3.1,"epss":0.0084,"slug":"cve-2024-32498-openstack-cinder-glance-and-nova-vulnerable-to-arbitrary-file","title":"PYSEC-2026-2493 - OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access","severity":"low","exploited":false,"published_at":"2026-07-13T14:36:32.3204+00:00","url":"https://junglewise.ai/threats/cve-2024-32498-openstack-cinder-glance-and-nova-vulnerable-to-arbitrary-file"},{"cve":"CVE-2022-4134","cvss":3.1,"epss":0.0033,"slug":"cve-2022-4134-openstack-glance-inclusion-of-functionality-from-untrusted-control","title":"PYSEC-2023-270 - A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integr","severity":"low","exploited":false,"published_at":"2023-03-06T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4134-openstack-glance-inclusion-of-functionality-from-untrusted-control"},{"cve":"CVE-2014-1948","cvss":3.1,"epss":0.0031,"slug":"cve-2014-1948-openstack-glance-sensitive-information-disclosure-via-logs","title":"PYSEC-2014-102 - OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swif","severity":"low","exploited":false,"published_at":"2014-02-14T15:55:00+00:00","url":"https://junglewise.ai/threats/cve-2014-1948-openstack-glance-sensitive-information-disclosure-via-logs"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}