Reference page — cumulative record through Thursday, August 20, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-34881
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF).
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C N L N 5.0 .0027 19.6 —
AFFECTED
Product Versions Fixed
Glance unspecified —
TIMELINE
Mar 31 Reserved by mitre
Mar 31 Published (CNA: mitre)
Aug 14 EXPLOIT PUBLISHED — CVE-2026-34881 (OpenStack Glance). Public exploit reference added.
Description
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| March 31, 2026 | Reserved | Reserved by mitre |
| March 31, 2026 | Published | Published (CNA: mitre) |
| August 14, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-34881 (OpenStack Glance). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| OpenStack | Glance | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-34881 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, August 20, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.