Input validation error in Glance - CVE-2026-34881
Published: April 28, 2026
Vulnerability details
The vulnerability allows a remote user to access internal services.
The vulnerability exists due to improper input validation in the web-download import method when following HTTP redirects. A remote user can provide a URL that passes validation and redirects to an internal or disallowed resource to access internal services.
Only the glance image import functionality is affected.
Affected software
Ubuntu
glance (Ubuntu package)
openstack-glance (Red Hat package)
How to mitigate CVE-2026-34881
glance (Ubuntu package) - addressed in versions 2:12.0.0-0ubuntu2+esm1, 2:16.0.1-0ubuntu1.1+esm2, 2:20.2.0-0ubuntu1.2+esm2
openstack-glance (Red Hat package) - update to 26.1.1-18.0.20260422134725.c2ac316.el9ost