{
  "threat_severity" : "Important",
  "public_date" : "2026-03-25T20:00:00Z",
  "bugzilla" : {
    "description" : "openstack-glance: OpenStack Glance: Server-Side Request Forgery leading to unauthorized internal network access",
    "id" : "2440368",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2440368"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.1",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-918",
  "details" : [ "OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.", "A flaw was found in OpenStack Glance. An authenticated user can exploit a Server-Side Request Forgery (SSRF) vulnerability within the web-download import feature. This vulnerability stems from inadequate validation of Uniform Resource Identifiers (URIs), which can be circumvented using HTTP redirects or alternative IP encodings. Successful exploitation allows an attacker to gain unauthorized access to internal network resources and potentially exfiltrate sensitive data." ],
  "statement" : "This is an IMPORTANT flaw in OpenStack Glance's web-download import feature allows an authenticated user to perform Server-Side Request Forgery (SSRF). The vulnerability arises from insufficient validation of URIs, which can be bypassed through HTTP redirects or alternative IP encodings. This enables an attacker to access internal network resources and potentially exfiltrate sensitive information within the cloud environment.",
  "acknowledgement" : "This issue was discovered by Abhishek Kekane (Red Hat) and Hyeongeun_Ji (Open the Window).",
  "affected_release" : [ {
    "product_name" : "Red Hat OpenStack Platform 16.2",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54757",
    "cpe" : "cpe:/a:redhat:openstack:16.2::el8",
    "package" : "openstack-glance-1:19.0.5-2.20260512165254.eb6ad61.el8ost"
  }, {
    "product_name" : "Red Hat OpenStack Services on OpenShift 18.0",
    "release_date" : "2026-07-15T00:00:00Z",
    "advisory" : "RHSA-2026:39812",
    "cpe" : "cpe:/a:redhat:openstack:18.0::el9",
    "package" : "openstack-glance-1:26.1.1-18.0.20260422134725.c2ac316.el9ost"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat OpenStack Platform 17.1",
    "fix_state" : "Affected",
    "package_name" : "openstack-glance",
    "cpe" : "cpe:/a:redhat:openstack:17.1"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-34881\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34881\nhttps://bugs.launchpad.net/glance/+bug/2138602" ],
  "name" : "CVE-2026-34881",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}