{
  "threat_severity" : "Important",
  "public_date" : "2026-09-04T08:44:49Z",
  "bugzilla" : {
    "description" : "openstack-glance: openstack-glance: SSRF via location API missing host validation",
    "id" : "2524517",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2524517"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.7",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
    "status" : "draft"
  },
  "cwe" : "CWE-918",
  "details" : [ "In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply the import_filtering_opts host restrictions. An authenticated user can add a location pointing to internal endpoints such as the cloud metadata service (169.254.169.254), and retrieve the response by downloading the image data. This affects both the new POST /v2/images/{id}/locations API and the old PATCH API when show_multiple_locations is enabled. Deployments with the HTTP store backend enabled are affected.", "A server-side request forgery (SSRF) vulnerability was found in OpenStack Glance. When the HTTP store backend is enabled, an authenticated user can add an image location URL pointing to internal network services. Glance validates only the URL scheme and does not check the host or IP address, allowing the server to make requests to arbitrary internal endpoints. An attacker can read the response by downloading the image, resulting in a full-read SSRF that may expose sensitive data such as cloud metadata credentials." ],
  "statement" : "This vulnerability is rated as Important because an authenticated project member can use the Glance location API as a full-read SSRF proxy to internal HTTP services, including cloud metadata credentials. The attack requires the HTTP store backend to be enabled. It is separate from the web-download SSRF fixed in CVE-2026-34881.\nRed Hat OpenStack Platform (RHOSP) and Red Hat OpenStack Services on OpenShift (RHOSO) deployments that ship Glance with HTTP store enabled are affected. Deployments without an HTTP store backend are not affected through the new POST /locations API. The older PATCH location API additionally requires show_multiple_locations=True, which is off by default.",
  "acknowledgement" : "Upstream acknowledges Cyril Roelandt (Red Hat) as the original reporter.",
  "package_state" : [ {
    "product_name" : "Red Hat OpenStack Platform 13 (Queens)",
    "fix_state" : "Not affected",
    "package_name" : "openstack-glance",
    "cpe" : "cpe:/a:redhat:openstack:13"
  }, {
    "product_name" : "Red Hat OpenStack Platform 16.2",
    "fix_state" : "Affected",
    "package_name" : "openstack-glance",
    "cpe" : "cpe:/a:redhat:openstack:16.2"
  }, {
    "product_name" : "Red Hat OpenStack Platform 17.1",
    "fix_state" : "Affected",
    "package_name" : "openstack-glance",
    "cpe" : "cpe:/a:redhat:openstack:17.1"
  }, {
    "product_name" : "Red Hat OpenStack Platform 18.0",
    "fix_state" : "Affected",
    "package_name" : "openstack-glance",
    "cpe" : "cpe:/a:redhat:openstack:18.0"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-71198\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-71198\nhttps://bugs.launchpad.net/glance/+bug/2161330\nhttps://redhat.atlassian.net/browse/OSPRH-34480" ],
  "name" : "CVE-2026-71198",
  "mitigation" : {
    "value" : "Config changes are workarounds. Upgrade to the patched Glance release.\nThe strongest config-only control is to remove the HTTP store from enabled_backends in glance-api.conf and restart Glance API.\nRestricting only add_image_location is not enough. Also restrict set_image_location (PATCH locations API), for example both to rule:service_api.\nEgress filtering on Glance API nodes is a partial control only.",
    "lang" : "en:us"
  },
  "csaw" : false
}