CVE-2026-34881
published 2026-03-31CVE-2026-34881: OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated…
PriorityP430medium5CVSS 3.1
AVNACLPRLUINSCCNILAN
EPSS
0.27%
18.3th percentile
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glance | < glance 2:31.0.0-3 (forky) | glance 2:31.0.0-3 (forky) |
| glance_project | glance | >= 0 < 2:31.0.0-3 | 2:31.0.0-3 |
| glance_project | glance | >= 0 < 29.2.0 | 29.2.0 |
| glance_project | glance | >= 30.0.0 < 30.2.0 | 30.2.0 |
| glance_project | glance | >= 31.0.0 < 31.1.0 | 31.1.0 |
| openstack | glance | < 29.1.1 | 29.1.1 |
| openstack | glance | — | — |
| openstack | glance | >= 30.0.0 < 30.1.1 | 30.1.1 |
| ubuntu | glance | — | — |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
osv5.0MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenStack Glance up to 29.1.0/30.1.0/31.0.0 ovf_process Image Import Plugin server-side request forgery (Nessus ID 304411)
vuldb·2026-07-02·CVSS 5.0
CVE-2026-34881 [MEDIUM] OpenStack Glance up to 29.1.0/30.1.0/31.0.0 ovf_process Image Import Plugin server-side request forgery (Nessus ID 304411)
A vulnerability identified as critical has been detected in OpenStack Glance up to 29.1.0/30.1.0/31.0.0. Affected by this vulnerability is an unknown functionality of the component ovf_process Image Import Plugin. Performing a manipulation results in server-side request forgery.
This vulnerability is identified as CVE-2026-34881. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
OSV
OpenStack Glance is affected by Server-Side Request Forgery (SSRF)
osv·2026-03-31
CVE-2026-34881 [MEDIUM] OpenStack Glance is affected by Server-Side Request Forgery (SSRF)
OpenStack Glance is affected by Server-Side Request Forgery (SSRF)
OpenStack Glance versions = 30.0.0 < 30.1.1, == 31.0.0 are affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only the glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.
OSV
CVE-2026-34881: OpenStack Glance =30
osv·2026-03-31·CVSS 5.0
CVE-2026-34881 [MEDIUM] CVE-2026-34881: OpenStack Glance =30
OpenStack Glance =30.0.0 <30.1.1, ==31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.
OSV
CVE-2026-34881: OpenStack Glance before 29
osv·2026-03-31·CVSS 5.0
CVE-2026-34881 [MEDIUM] CVE-2026-34881: OpenStack Glance before 29
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.
GHSA
OpenStack Glance is affected by Server-Side Request Forgery (SSRF)
ghsa·2026-03-31
CVE-2026-34881 [MEDIUM] CWE-918 OpenStack Glance is affected by Server-Side Request Forgery (SSRF)
OpenStack Glance is affected by Server-Side Request Forgery (SSRF)
OpenStack Glance versions = 30.0.0 < 30.1.1, == 31.0.0 are affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only the glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.
Ubuntu
OpenStack Glance vulnerabilities
vendor_ubuntu·2026-04-22·CVSS 6.5
CVE-2024-32498 [MEDIUM] OpenStack Glance vulnerabilities
Title: OpenStack Glance vulnerabilities
Summary: Several security issues were fixed in OpenStack Glance.
Martin Kaesberger discovered that OpenStack Glance's image processing could
return the contents of arbitrary files. An attacker could possibly use this
issue to exfiltrate sensitive data. This issue only affected Ubuntu 16.04
LTS and Ubuntu 18.04 LTS. (CVE-2024-32498)
Hyeongeun Ji and Abhishek Kekane discovered several server-side request
forgery vulnerabilities in OpenStack Glance's image import. An attacker
could possibly use this issue to bypass URL validation checks and redirect
to internal services. This issue only affected Ubuntu 18.04 LTS and Ubuntu
20.04 LTS. (CVE-2026-34881)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
OpenStack Glance: OpenStack Glance: Server-Side Request Forgery via HTTP redirects in image import
vendor_redhat·2026-03-31·CVSS 5.0
CVE-2026-34881 [MEDIUM] CWE-918 OpenStack Glance: OpenStack Glance: Server-Side Request Forgery via HTTP redirects in image import
OpenStack Glance: OpenStack Glance: Server-Side Request Forgery via HTTP redirects in image import
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.
A flaw was found in OpenStack Glance. An authenticated user can exploit this Server-Side Request Forgery (SSRF) vulnerability by using HTTP redirects to bypass URL validation checks. This allows the user to redirect to internal services.
Debian
CVE-2026-34881: glance - OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Se...
vendor_debian·2026·CVSS 5.0
CVE-2026-34881 [MEDIUM] CVE-2026-34881: glance - OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Se...
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2:31.0.0-3)
sid: resolved (fixed in 2:31.0.0-3)
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-34881 OpenStack Glance: OpenStack Glance: Server-Side Request Forgery via HTTP redirects in image import
bugzilla·2026-03-31·CVSS 5.0
CVE-2026-34881 [MEDIUM] CVE-2026-34881 OpenStack Glance: OpenStack Glance: Server-Side Request Forgery via HTTP redirects in image import
CVE-2026-34881 OpenStack Glance: OpenStack Glance: Server-Side Request Forgery via HTTP redirects in image import
OpenStack Glance =30.0.0 <30.1.1, ==31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.
Wiz
CVE-2026-34881 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-34881 [MEDIUM] CVE-2026-34881 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34881 :
OpenStack Glance vulnerability analysis and mitigation
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.
Source : NVD
## 5
Score
Published March 31, 2026
Severity MEDIUM
CNA Score 5.0
Affected Technologies
OpenStack Glance
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probabil
https://bugs.launchpad.net/glance/+bug/2138602https://security.openstack.org/ossa/OSSA-2026-004.htmlhttps://access.redhat.com/errata/RHSA-2026:39812https://access.redhat.com/security/cve/CVE-2026-34881https://bugs.launchpad.net/glance/+bug/2138602https://bugzilla.redhat.com/show_bug.cgi?id=2440368https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34881.json
2026-03-31
Published