#1146594 CVE-2026-71196, CVE-2026-71197, CVE-2026-71198, OSSA-2026-038: Multiple SSRF vulnerabilities in Glance web-download and HTTP image APIs

Package:
glance
Source:
glance
Submitter:
Thomas Goirand
Date:
2026-09-03 20:45:02 UTC
Severity:
normal
Tags:
#1146594#5
Date:
2026-09-03 17:07:25 UTC
From:
To:
As per upstream announce here:
https://security.openstack.org/ossa/OSSA-2026-038.html


Date:
    September 03, 2026
CVE:
    CVE-2026-71196, CVE-2026-71197, CVE-2026-71198

Affects
    Glance: >=16.0.0 <30.2.1, >=31.0.0 <31.1.1, >=32.0.0 <32.0.1

Description:
Sergey Kanibor (Luntry), Sami Yessou (switch.ch), and Abhishek Kekane (Red Hat)
reported three related SSRF vulnerabilities in OpenStack Glance.

The web-download import method ships with insecure default filtering that
permits authenticated users to fetch arbitrary internal URLs, including cloud
metadata endpoints. The URI validator does not perform DNS resolution before
applying host filters, enabling bypass via attacker-controlled domains and
DNS rebinding attacks. The HTTP image location API lacks host filtering
entirely when the HTTP store is enabled, and fetched content is stored as
image data accessible for download, converting blind SSRF into full-read
exfiltration.

All Glance deployments using the web-download import method or HTTP image
location APIs are affected.

Patches:
https://review.opendev.org/1003822 (2025.1/epoxy)
https://review.opendev.org/1003823 (2025.1/epoxy)
https://review.opendev.org/1003824 (2025.1/epoxy)
https://review.opendev.org/1003825 (2025.1/epoxy)

https://review.opendev.org/1003816 (2025.2/flamingo)
https://review.opendev.org/1003817 (2025.2/flamingo)
https://review.opendev.org/1003818 (2025.2/flamingo)
https://review.opendev.org/1003819 (2025.2/flamingo)

https://review.opendev.org/1003812 (2026.1/gazpacho)
https://review.opendev.org/1003813 (2026.1/gazpacho)
https://review.opendev.org/1003814 (2026.1/gazpacho)
https://review.opendev.org/1003815 (2026.1/gazpacho)

https://review.opendev.org/1003805 (2026.2/hibiscus (development))
https://review.opendev.org/1003806 (2026.2/hibiscus (development))
https://review.opendev.org/1003807 (2026.2/hibiscus (development))
https://review.opendev.org/1003808 (2026.2/hibiscus (development))

Credits

    Sergey Kanibor from Luntry (CVE-2026-71196, CVE-2026-71197)
    Sami Yessou from switch.ch (CVE-2026-71196)
    Abhishek Kekane from Red Hat (CVE-2026-71198)

References
https://launchpad.net/bugs/2158998
https://launchpad.net/bugs/2158999
https://launchpad.net/bugs/2161330
https://launchpad.net/bugs/2160020
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71196
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71197
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71198

Notes
    All four commits in each patch set are interdependent and must be applied
together, in the order listed above, as each builds on the previous. The DoS
issue (LP#2160020) is addressed as part of this coordinated fix.

    A related Tempest test compatibility fix was proposed at
https://review.opendev.org/1003560

#1146594#8
Date:
2026-09-03 17:28:16 UTC
From:
To:
Hello,

Bug #1146594 in glance reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/glance/-/commit/8c132fb27d442a14673230db9a19d7c292247558
------------------------------------------------------------------------
* CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF
    vulnerabilities. Applied upstream patches:
    - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch
    - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch
    - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch
    - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch
    (Closes: #1146594)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1146594

#1146594#13
Date:
2026-09-03 17:29:08 UTC
From:
To:
Hello,

Bug #1146594 in glance reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/glance/-/commit/e4a3c605a0d016b71d2af644d4edf31f5b71074d
------------------------------------------------------------------------
* CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF
    vulnerabilities. Applied upstream patches:
    - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch
    - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch
    - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch
    - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch
    (Closes: #1146594)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1146594

#1146594#16
Date:
2026-09-03 17:32:21 UTC
From:
To:
Hello,

Bug #1146594 in glance reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/glance/-/commit/d8942aa30e9c5b0264d1e60fb9b87866f4cd16b3
------------------------------------------------------------------------
* CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF
    vulnerabilities. Applied upstream patches:
    - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch
    - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch
    - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch
    - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch
    (Closes: #1146594)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1146594

#1146594#19
Date:
2026-09-03 17:32:31 UTC
From:
To:
Hello,

Bug #1146594 in glance reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/glance/-/commit/4fa3498f5c9fc51cacb7994f9b8cf4ee137672ef
------------------------------------------------------------------------
* CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF
    vulnerabilities. Applied upstream patches:
    - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch
    - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch
    - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch
    - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch
    - CVE-2026-71196-71197-71198_5_fix-unit-tests.patch
    (Closes: #1146594)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1146594

#1146594#22
Date:
2026-09-03 17:32:33 UTC
From:
To:
Hello,

Bug #1146594 in glance reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/glance/-/commit/3a81726c0fc8be46d330e51d808f7b841f5ec683
------------------------------------------------------------------------
* CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF
    vulnerabilities. Applied upstream patches:
    - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch
    - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch
    - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch
    - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch
    (Closes: #1146594)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1146594

#1146594#25
Date:
2026-09-03 17:33:20 UTC
From:
To:
Hello,

Bug #1146594 in glance reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/glance/-/commit/9c9d1cd29e28bb3e52175bc96b6c375dc972acad
------------------------------------------------------------------------
* CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF
    vulnerabilities. Applied upstream patches:
    - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch
    - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch
    - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch
    - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch
    - CVE-2026-71196-71197-71198_5_fix-unit-tests.patch
    (Closes: #1146594)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1146594

#1146594#28
Date:
2026-09-03 17:33:50 UTC
From:
To:
Hello,

Bug #1146594 in glance reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/glance/-/commit/c6225211f6e1285ea80c9e0db5af1c8d603225e1
------------------------------------------------------------------------
* CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF
    vulnerabilities. Applied upstream patches:
    - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch
    - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch
    - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch
    - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch
    (Closes: #1146594)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1146594

#1146594#31
Date:
2026-09-03 17:34:23 UTC
From:
To:
Hello,

Bug #1146594 in glance reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/glance/-/commit/bee96ad213bf8b40ada235586efa48bc959b5df1
------------------------------------------------------------------------
* CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF
    vulnerabilities. Applied upstream patches:
    - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch
    - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch
    - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch
    - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch
    - CVE-2026-71196-71197-71198_5_fix-unit-tests.patch
    (Closes: #1146594)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1146594

#1146594#38
Date:
2026-09-03 19:52:24 UTC
From:
To:
Hello,

Bug #1146594 in glance reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/glance/-/commit/89e7cf2f1fd80e2ee9bf33037ec68c792616b2a6
------------------------------------------------------------------------
* CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF
    vulnerabilities. Applied upstream patches:
    - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch
    - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch
    - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch
    - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch
    (Closes: #1146594)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1146594

#1146594#41
Date:
2026-09-03 19:52:38 UTC
From:
To:
Hello,

Bug #1146594 in glance reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/glance/-/commit/a1321f3836c04c27a240e455ed2b1d73fdf6262b
------------------------------------------------------------------------
* CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF
    vulnerabilities. Applied upstream patches:
    - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch
    - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch
    - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch
    - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch
    (Closes: #1146594)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1146594

#1146594#46
Date:
2026-09-03 20:42:45 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
glance, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1146594@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated glance package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 28 Aug 2026 10:50:37 +0200
Source: glance
Architecture: source
Version: 2:32.0.0-4
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1146594
Changes:
 glance (2:32.0.0-4) unstable; urgency=high
 .
   * CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF
     vulnerabilities. Applied upstream patches:
     - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch
     - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch
     - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch
     - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch
     (Closes: #1146594)
Checksums-Sha1:
 b3184118dac8b7c3b2f7b026f468af8c6d25b04b 3707 glance_32.0.0-4.dsc
 520c622c2668c8afdceb445e682b61649aa076f1 39292 glance_32.0.0-4.debian.tar.xz
 9a9ceeead2fbe5e5ab441cff5e0b5bb4ef1268d2 18727 glance_32.0.0-4_amd64.buildinfo
Checksums-Sha256:
 0172026b91a6927487deb323ff94ea0f631a7a9c86b7255a381beb3b52e47f13 3707 glance_32.0.0-4.dsc
 865d7eebb128b8f0697a618f2c7ffa5d24636fc16448d57b5867494dcdee52a2 39292 glance_32.0.0-4.debian.tar.xz
 7c30f0786068aa2a791d9bbed0bbfbc75b234332578433ee46b9ff31c678cc5f 18727 glance_32.0.0-4_amd64.buildinfo
Files:
 6f0580204d0dd790c57d636f5f498067 3707 net optional glance_32.0.0-4.dsc
 8d9be09dc2bbd590d1597103a6dcc419 39292 net optional glance_32.0.0-4.debian.tar.xz
 6d225b0fdbb41267de4ac5c690b3bf60 18727 net optional glance_32.0.0-4_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqZ0AEACgkQ1BatFaxr
Q/4HVA//TKQV3lQuJSb9lq5Wf+ODT9Qyv7+b90v007gfHzHQGBrep9G+yMRcEZEG
8Qud5c7Kxt2vvOiqPiX+so4btAEEj5thyAO9PD672uCnrBB8tZZaRXaZ8SIv6r0+
T6x/hScvCUPmvoMm0T9YnGryFyBcDcWXGQg47tkKdMw+DapGZtks20CMeo3IUBbw
heLdW3o1WEceMWvsK7fsRDMdGXvQmN2oq14gc1Q/DuPWUq02qSB+kD+q1nQQ4riF
4CSAzd36ubCdj9ttefb/tXd9xLAsfBtO42t7x69Bnq/aHUM46nRZiwQVOCF9jrT7
kR/NIE6TbnzF575d5nDmk0qfJihRlAikbDwEK+TPgKFjrWTogFCHEV4ntH3JRfIG
fv2VYf+tPNdmN4vIorZwt0vXmzMeutqy/hlTS6SUje1/n2tQszn7UqnLFFt6YyAR
IEmJeloSjJA/g+4uC7LHDaYk/KRIUNJNd3BQbng4QlYvQBKfqZH505e+ZzucZE+p
TqrKoJHH0HjlKYLLhpcwhOITB66MfzMhVOTWFHQRL3b6e3cX/qyA+YpMlxD7cOh1
xPSTsKRS2vzTDBvtmlGCbNuL9Hyo4D6X63mLUXMUXBdpIQecMdMhKsv/xJJH3MZU
8i3VJoZzeTo4tQFzbEn8z9rFB8LYVd5jjcNdfjNHPTLlDfffdXk=
=5QT2
-----END PGP SIGNATURE-----