OpenStack / Glance
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-71198 | openstack-glance: openstack-glance: SSRF via location API missing host validation | HIGH | 7.0 | Sep 14, 2026 |
| CVE-2026-77648 | glance: OpenStack Glance: Server-Side Request Forgery allows internal URL access by administrators | LOW | 2.2 | Aug 20, 2026 |
| CVE-2026-34881 | openstack-glance: OpenStack Glance: Server-Side Request Forgery leading to unauthorized internal network access | HIGH | 7.1 | Mar 31, 2026 |
| CVE-2024-32498 | OpenStack: malicious qcow2/vmdk images | HIGH | 7.1 | Jul 5, 2024 |
| CVE-2022-4134 | openstack: glance & ceph conflict which allows image tampering | MEDIUM | 4.8 | Mar 6, 2023 |
| CVE-2022-47951 | openstack: Arbitrary file access through custom VMDK flat descriptor | HIGH | 7.7 | Jan 26, 2023 |
| CVE-2016-8611 | openstack-glance: Glance Image service v1 and v2 api image-create vulnerability | MEDIUM | 6.5 | Jul 31, 2018 |
| CVE-2015-8234 | openstack-glance: MD5 used for cryptographic signature verification | MEDIUM | 5.5 | Mar 29, 2017 |
| CVE-2017-7200 | openstack-glance: API v1 copy_from reveals network details | MEDIUM | 5.8 | Mar 21, 2017 |
| CVE-2015-5162 | openstack-nova/glance/cinder: Malicious image may exhaust resources | HIGH | 7.5 | Oct 7, 2016 |
| CVE-2015-5163 | openstack-glance: Glance v2 API host file disclosure through qcow2 backing file | HIGH | 7.1 | Aug 19, 2015 |
| CVE-2015-3289 | openstack-glance: potential resource exhaustion task flow API | MEDIUM | 4.0 | Aug 14, 2015 |
| CVE-2013-4428 | Glance: image_download policy not enforced for cached images | LOW | 3.5 | Oct 27, 2013 |
| CVE-2013-1840 | The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which… | MEDIUM | 6.5 | Mar 22, 2013 |
Showing 1 to 12 of 12 CVEs