important · Edge — OpenStack
Authenticated Glance users can turn image imports into full-read requests against metadata and internal services.
Affects
OpenStack Glance, the image-management service used by private and public OpenStack clouds.
Weak destination filtering, DNS-rebinding gaps, and an unfiltered HTTP image store let an authorized importer select an internal resource.
Detail and 2 sources
The HTTP-store path saves the response as downloadable image data, and OpenStack has published coordinated patches.
Sources
ResearchOSSA-2026-038: Multiple SSRF vulnerabilities in Glance web-download and HTTP image APIs — OpenStack Security Advisories 0.0.1.dev390 documentationResearch[oss-security] [OSSA-2026-038] OpenStack Glance: Multiple SSRF vulnerabilities in web-download and HTTP image APIs (CVE-2026-71196, CVE-2026-71197, CVE-2026-71198)