Input validation error in Glance - CVE-2026-34881

 

Input validation error in Glance - CVE-2026-34881

Published: April 28, 2026


Vulnerability identifier: #VU128271
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-34881
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access internal services.

The vulnerability exists due to improper input validation in the web-download import method when following HTTP redirects. A remote user can provide a URL that passes validation and redirects to an internal or disallowed resource to access internal services.

Only the glance image import functionality is affected.


Affected software

Glance
Ubuntu
glance (Ubuntu package)
openstack-glance (Red Hat package)

How to mitigate CVE-2026-34881

Install security update from vendor's website.

Glance - update to 32.0.0
glance (Ubuntu package) - addressed in versions 2:12.0.0-0ubuntu2+esm1, 2:16.0.1-0ubuntu1.1+esm2, 2:20.2.0-0ubuntu1.2+esm2
openstack-glance (Red Hat package) - update to 26.1.1-18.0.20260422134725.c2ac316.el9ost

External References

Related Security Bulletins