Skip to content
VulniPulse
Highest advisory severityLow 1 vendor · 1 advisory

CVE-2026-77648

CVE-2026-77648: 1 tracked advisory record across Red Hat. Compare vendor sources.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityLow2.2

    Low [CVE-2026-77648] Server-Side Request Forgery allows internal URL access by administrators

    CVE-2026-77648Source published Source updated

    In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases. A privileged administrator could exploit a vulnerability in the `/v2/tasks` API by crafting a specific import task. This action bypasses security filtering, enabling the administrator to perform Server-Side Request Forgery (SSRF). As a result, an attacker could access and retrieve sensitive information from internal URLs within the Glance service network. Red Hat severity: Low — CVSS 2.2 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N). Weakness…

    Affected products in this advisory
    No product details extracted. Check the source bulletin.
    Source-reported affected versions
    • 32.0.0
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    No mitigation guidance extracted; consult the source.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery