#1149967 glance: CVE-2026-51773

Package:
src:glance
Source:
src:glance
Submitter:
Salvatore Bonaccorso
Date:
2026-10-09 11:37:02 UTC
Severity:
normal
Tags:
#1149967#5
Date:
2026-10-04 19:46:01 UTC
From:
To:
Hi,

The following vulnerability was published for glance.

CVE-2026-51773[0]:
| An issue in the VMware datastore driver of OpenStack glance_store.
| When an authenticated attacker provides a maliciously crafted image
| location URI pointing to an external server, the _retry_request
| function fails to validate the destination host before attaching
| sensitive authentication headers.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-51773
https://www.cve.org/CVERecord?id=CVE-2026-51773
[1] https://bugs.launchpad.net/glance/+bug/2167929

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1149967#12
Date:
2026-10-09 11:13:50 UTC
From:
To:
Hello,

Bug #1149967 in python-glance-store reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/libs/python-glance-store/-/commit/cf44bc0df8590e92c9afc4d1a2c09b6245595cca
* CVE-2026-51773: Fix VIM session cookie leak to untrusted hosts in the
  VMware datastore driver: _retry_request() now refuses to send any
  request, and the vmware_soap_session cookie, to a host other than the
  configured vmware_server_host, so a user-supplied vsphere:// image
  location cannot exfiltrate vCenter credentials when
  show_multiple_locations is enabled (Closes: #1149967):
  - CVE-2026-51773_refuse-vim-cookie-to-untrusted-hosts.patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149967

#1149967#19
Date:
2026-10-09 11:34:16 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
python-glance-store, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1149967@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated python-glance-store package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 09 Oct 2026 13:04:02 +0200
Source: python-glance-store
Architecture: source
Version: 5.7.0-3
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1149967
Changes:
 python-glance-store (5.7.0-3) unstable; urgency=medium
 .
   * CVE-2026-51773: Fix VIM session cookie leak to untrusted hosts in the
     VMware datastore driver: _retry_request() now refuses to send any
     request, and the vmware_soap_session cookie, to a host other than the
     configured vmware_server_host, so a user-supplied vsphere:// image
     location cannot exfiltrate vCenter credentials when
     show_multiple_locations is enabled (Closes: #1149967):
     - CVE-2026-51773_refuse-vim-cookie-to-untrusted-hosts.patch
Checksums-Sha1:
 695113230fbd4e5adf361ed8f77cd91419a91d58 3183 python-glance-store_5.7.0-3.dsc
 8a11fd3f3d84607a5ff9c8f8b20f68d48f131b99 9656 python-glance-store_5.7.0-3.debian.tar.xz
 51c8274c74f64f3df4682a27191e1bf4e1cab6b1 13549 python-glance-store_5.7.0-3_amd64.buildinfo
Checksums-Sha256:
 f40bdd16fb1a5aafd7c928c3c5b3a2c54416c8e30724343ebbed059f9a6dbb16 3183 python-glance-store_5.7.0-3.dsc
 4b631f6f17162b3e62d20eaa30bca7ce1cf645ee50f958259be7beb79c5f255f 9656 python-glance-store_5.7.0-3.debian.tar.xz
 c8b0b44a76a6efdf76440779f8652e7a1cb4a3cd9cd7c63c57ab66ee1839521e 13549 python-glance-store_5.7.0-3_amd64.buildinfo
Files:
 0ea6f3138bc8e26e16fb877ee0de610d 3183 python optional python-glance-store_5.7.0-3.dsc
 0109e88ae5c745c5253c9e6e5b6dee3c 9656 python optional python-glance-store_5.7.0-3.debian.tar.xz
 5372e190d35535223c263aa84e6fd998 13549 python optional python-glance-store_5.7.0-3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmrIzHIACgkQ1BatFaxr
Q/7qwg//cvAmJiMgGZBMigyI9nOsIBJx2vuS+MvrCc8F2P4u4+2Omw5ePrhYNIu6
kYK6gLtP81ow2L/nI865I/Snc1xriMw0n0HIF3aFYygujQb68pOKXcwfVLRo3zMO
sIAUHTk++9NgkgeupCjICshmsdzSz5HvN6BEwMIRG1eBJTkZmBitRZ7J1tw21ROE
PQQefJUyju9SkyzUSDbTrHvj0dOcLI6uIZlDuHzXn/ZNd1AvuLcZQoZJLEbdGFLQ
6n2G6+QiEfxDXxQGbFF6ilhow4/qR2lmLrLFLXeE/MbPpAwaJEhVINAwVIZgHQpy
24rf9KjpLqV9WGz9Wr9v3YOchNIpmZn4S/GZSqCCkZIOPq0MEzq56xFJKreFjVao
XA2y2555nt/yrXeas5Fo8taEdd+3mm+BlwffLRPCMSkVmVb4TRjPtJv7logOsLUu
0oQa7yF5PB6Iv0j8I2DNBzfVJp0LwbESneVZyxF1gHOvAeQhv9I4IteG9wQzlqvc
O6Rl2uj1jB+bwO0uP8gkXQ8qNvNVJ4GFC2C6clzc2sQthcCzAQPf6Gd+CUCWNXq+
sd3CzNYHs8PvlN0QgKZOl0+6tT3ZwENJ9ATUsQWyfMVKZwTzyZ28n+YcWbbWUQN9
vxmjSA71jAIgf0zNzyK7i6bDd5p3W7q/t4kANxSuqpvYpf++2XE=
=iwm0
-----END PGP SIGNATURE-----