CVE-2026-34881 Details
Description
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.
A Server-Side Request Forgery (SSRF) vulnerability has been identified in OpenStack Glance versions prior to 29.1.1, 30.0.0 through 30.1.1, and 31.0.0. This vulnerability allows authenticated users to bypass URL validation checks in the image import functionality, specifically through HTTP redirects. The issue is present in the 'web-download' and 'glance-download' import methods, as well as the optional 'ovf_process' image import plugin.
Users can update to OpenStack Glance versions 29.2.0, 30.2.0, 31.1.0, or 32.0.0.0rc2, all of which include the necessary fix. Instructions for applying the update can be found in the OpenStack Glance release notes.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:39812 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:54757 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-34881 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2440368 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34881.json | redhat-SADP | |
| https://bugs.launchpad.net/glance/+bug/2138602 | CISA-ADP | ExploitIssue TrackingThird Party Advisory |
| https://bugs.launchpad.net/glance/+bug/2138602 | [email protected] | ExploitIssue TrackingThird Party Advisory |
| https://security.openstack.org/ossa/OSSA-2026-004.html | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | redhat-SADP |
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openstack glance | < 29.1.1 >= 30.0.0, < 30.1.1 31.0.0 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 14, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 14, 2026 | Initial Analysis | [email protected] |
| Apr 2, 2026 | CVE Modified | [email protected] |
| Mar 31, 2026 | CVE Modified | CISA-ADP |
| Mar 31, 2026 | New CVE Received | [email protected] |