As per upstream announce here: https://security.openstack.org/ossa/OSSA-2026-038.html Date: September 03, 2026 CVE: CVE-2026-71196, CVE-2026-71197, CVE-2026-71198 Affects Glance: >=16.0.0 <30.2.1, >=31.0.0 <31.1.1, >=32.0.0 <32.0.1 Description: Sergey Kanibor (Luntry), Sami Yessou (switch.ch), and Abhishek Kekane (Red Hat) reported three related SSRF vulnerabilities in OpenStack Glance. The web-download import method ships with insecure default filtering that permits authenticated users to fetch arbitrary internal URLs, including cloud metadata endpoints. The URI validator does not perform DNS resolution before applying host filters, enabling bypass via attacker-controlled domains and DNS rebinding attacks. The HTTP image location API lacks host filtering entirely when the HTTP store is enabled, and fetched content is stored as image data accessible for download, converting blind SSRF into full-read exfiltration. All Glance deployments using the web-download import method or HTTP image location APIs are affected. Patches: https://review.opendev.org/1003822 (2025.1/epoxy) https://review.opendev.org/1003823 (2025.1/epoxy) https://review.opendev.org/1003824 (2025.1/epoxy) https://review.opendev.org/1003825 (2025.1/epoxy) https://review.opendev.org/1003816 (2025.2/flamingo) https://review.opendev.org/1003817 (2025.2/flamingo) https://review.opendev.org/1003818 (2025.2/flamingo) https://review.opendev.org/1003819 (2025.2/flamingo) https://review.opendev.org/1003812 (2026.1/gazpacho) https://review.opendev.org/1003813 (2026.1/gazpacho) https://review.opendev.org/1003814 (2026.1/gazpacho) https://review.opendev.org/1003815 (2026.1/gazpacho) https://review.opendev.org/1003805 (2026.2/hibiscus (development)) https://review.opendev.org/1003806 (2026.2/hibiscus (development)) https://review.opendev.org/1003807 (2026.2/hibiscus (development)) https://review.opendev.org/1003808 (2026.2/hibiscus (development)) Credits Sergey Kanibor from Luntry (CVE-2026-71196, CVE-2026-71197) Sami Yessou from switch.ch (CVE-2026-71196) Abhishek Kekane from Red Hat (CVE-2026-71198) References https://launchpad.net/bugs/2158998 https://launchpad.net/bugs/2158999 https://launchpad.net/bugs/2161330 https://launchpad.net/bugs/2160020 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71196 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71197 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71198 Notes All four commits in each patch set are interdependent and must be applied together, in the order listed above, as each builds on the previous. The DoS issue (LP#2160020) is addressed as part of this coordinated fix. A related Tempest test compatibility fix was proposed at https://review.opendev.org/1003560
Hello, Bug #1146594 in glance reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/glance/-/commit/8c132fb27d442a14673230db9a19d7c292247558 ------------------------------------------------------------------------ * CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF vulnerabilities. Applied upstream patches: - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch (Closes: #1146594) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1146594
Hello, Bug #1146594 in glance reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/glance/-/commit/e4a3c605a0d016b71d2af644d4edf31f5b71074d ------------------------------------------------------------------------ * CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF vulnerabilities. Applied upstream patches: - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch (Closes: #1146594) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1146594
Hello, Bug #1146594 in glance reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/glance/-/commit/d8942aa30e9c5b0264d1e60fb9b87866f4cd16b3 ------------------------------------------------------------------------ * CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF vulnerabilities. Applied upstream patches: - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch (Closes: #1146594) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1146594
Hello, Bug #1146594 in glance reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/glance/-/commit/4fa3498f5c9fc51cacb7994f9b8cf4ee137672ef ------------------------------------------------------------------------ * CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF vulnerabilities. Applied upstream patches: - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch - CVE-2026-71196-71197-71198_5_fix-unit-tests.patch (Closes: #1146594) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1146594
Hello, Bug #1146594 in glance reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/glance/-/commit/3a81726c0fc8be46d330e51d808f7b841f5ec683 ------------------------------------------------------------------------ * CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF vulnerabilities. Applied upstream patches: - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch (Closes: #1146594) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1146594
Hello, Bug #1146594 in glance reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/glance/-/commit/9c9d1cd29e28bb3e52175bc96b6c375dc972acad ------------------------------------------------------------------------ * CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF vulnerabilities. Applied upstream patches: - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch - CVE-2026-71196-71197-71198_5_fix-unit-tests.patch (Closes: #1146594) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1146594
Hello, Bug #1146594 in glance reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/glance/-/commit/c6225211f6e1285ea80c9e0db5af1c8d603225e1 ------------------------------------------------------------------------ * CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF vulnerabilities. Applied upstream patches: - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch (Closes: #1146594) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1146594
Hello, Bug #1146594 in glance reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/glance/-/commit/bee96ad213bf8b40ada235586efa48bc959b5df1 ------------------------------------------------------------------------ * CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF vulnerabilities. Applied upstream patches: - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch - CVE-2026-71196-71197-71198_5_fix-unit-tests.patch (Closes: #1146594) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1146594
Hello, Bug #1146594 in glance reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/glance/-/commit/89e7cf2f1fd80e2ee9bf33037ec68c792616b2a6 ------------------------------------------------------------------------ * CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF vulnerabilities. Applied upstream patches: - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch (Closes: #1146594) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1146594
Hello, Bug #1146594 in glance reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/glance/-/commit/a1321f3836c04c27a240e455ed2b1d73fdf6262b ------------------------------------------------------------------------ * CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF vulnerabilities. Applied upstream patches: - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch (Closes: #1146594) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1146594
We believe that the bug you reported is fixed in the latest version of
glance, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1146594@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated glance package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 28 Aug 2026 10:50:37 +0200
Source: glance
Architecture: source
Version: 2:32.0.0-4
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1146594
Changes:
glance (2:32.0.0-4) unstable; urgency=high
.
* CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF
vulnerabilities. Applied upstream patches:
- CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch
- CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch
- CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch
- CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch
(Closes: #1146594)
Checksums-Sha1:
b3184118dac8b7c3b2f7b026f468af8c6d25b04b 3707 glance_32.0.0-4.dsc
520c622c2668c8afdceb445e682b61649aa076f1 39292 glance_32.0.0-4.debian.tar.xz
9a9ceeead2fbe5e5ab441cff5e0b5bb4ef1268d2 18727 glance_32.0.0-4_amd64.buildinfo
Checksums-Sha256:
0172026b91a6927487deb323ff94ea0f631a7a9c86b7255a381beb3b52e47f13 3707 glance_32.0.0-4.dsc
865d7eebb128b8f0697a618f2c7ffa5d24636fc16448d57b5867494dcdee52a2 39292 glance_32.0.0-4.debian.tar.xz
7c30f0786068aa2a791d9bbed0bbfbc75b234332578433ee46b9ff31c678cc5f 18727 glance_32.0.0-4_amd64.buildinfo
Files:
6f0580204d0dd790c57d636f5f498067 3707 net optional glance_32.0.0-4.dsc
8d9be09dc2bbd590d1597103a6dcc419 39292 net optional glance_32.0.0-4.debian.tar.xz
6d225b0fdbb41267de4ac5c690b3bf60 18727 net optional glance_32.0.0-4_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqZ0AEACgkQ1BatFaxr
Q/4HVA//TKQV3lQuJSb9lq5Wf+ODT9Qyv7+b90v007gfHzHQGBrep9G+yMRcEZEG
8Qud5c7Kxt2vvOiqPiX+so4btAEEj5thyAO9PD672uCnrBB8tZZaRXaZ8SIv6r0+
T6x/hScvCUPmvoMm0T9YnGryFyBcDcWXGQg47tkKdMw+DapGZtks20CMeo3IUBbw
heLdW3o1WEceMWvsK7fsRDMdGXvQmN2oq14gc1Q/DuPWUq02qSB+kD+q1nQQ4riF
4CSAzd36ubCdj9ttefb/tXd9xLAsfBtO42t7x69Bnq/aHUM46nRZiwQVOCF9jrT7
kR/NIE6TbnzF575d5nDmk0qfJihRlAikbDwEK+TPgKFjrWTogFCHEV4ntH3JRfIG
fv2VYf+tPNdmN4vIorZwt0vXmzMeutqy/hlTS6SUje1/n2tQszn7UqnLFFt6YyAR
IEmJeloSjJA/g+4uC7LHDaYk/KRIUNJNd3BQbng4QlYvQBKfqZH505e+ZzucZE+p
TqrKoJHH0HjlKYLLhpcwhOITB66MfzMhVOTWFHQRL3b6e3cX/qyA+YpMlxD7cOh1
xPSTsKRS2vzTDBvtmlGCbNuL9Hyo4D6X63mLUXMUXBdpIQecMdMhKsv/xJJH3MZU
8i3VJoZzeTo4tQFzbEn8z9rFB8LYVd5jjcNdfjNHPTLlDfffdXk=
=5QT2
-----END PGP SIGNATURE-----