LOWVulnerability
CVE-2026-77648
In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.
Properties
- severity
- LOW
- score
- 2.2
- epss_score
- 0.00192
- cve_id
- CVE-2026-77648
- vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
- published_at
- 2026-08-20T23:16:28.797
- last_modified
- 2026-09-09T16:03:22.897
- epss_percentile
- 0.08929
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Server-Side Request Forgery (SSRF)
Explore deeper with Ninja Signal's threat intelligence graph