An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request …
High CVSS 8.1
Summary
An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destination host before attaching sensitive authentication headers.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/sadandbset/CVE-2026-51772-CVE-2026-51773
- https://github.com/sadandbset/CVE-2026-51772-CVE-2026-51773/blob/main/CVE-2026-51773.md
Timeline
- nvd_ingest NVD