CVE-2026-77648
CVE-2026-77648: 1 tracked advisory record across Red Hat. Compare vendor sources.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityLow2.2
Low [CVE-2026-77648] Server-Side Request Forgery allows internal URL access by administrators
CVE-2026-77648Source published Source updated
In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases. A privileged administrator could exploit a vulnerability in the `/v2/tasks` API by crafting a specific import task. This action bypasses security filtering, enabling the administrator to perform Server-Side Request Forgery (SSRF). As a result, an attacker could access and retrieve sensitive information from internal URLs within the Glance service network. Red Hat severity: Low — CVSS 2.2 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N). Weakness…
- Affected products in this advisory
- No product details extracted. Check the source bulletin.
- Source-reported affected versions
- 32.0.0
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.