vulnti.work

An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request …

High CVSS 8.1
CVECVE-2026-51773
First seen2026-09-25 18:16 UTC
Disclosed2026-09-25 13:17 UTC
Last updated2026-09-25 18:16 UTC
Channel statusauto

Summary

An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destination host before attaching sensitive authentication headers.

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD