GPU VulnDB

Database/Control plane, storage & DevOps

OpenStack glance_store: VMware datastore driver sends authentication headers to an attacker-supplied image location host

CVSS 8.1CVE-2026-51773Control plane, storage & DevOpscurated

Impact

_retry_request in the VMware datastore driver does not validate the destination host before attaching authentication headers, so an image location URI pointing at an external server makes Glance deliver its datastore credentials there. An authenticated user who can set an image location gets the vCenter datastore credentials Glance holds, plus a request-forgery primitive from Glance's network position inside the management network. For an operator running OpenStack as the fleet's control plane, that is a credential leak into the virtualization layer where the GPU instances are created. The available record is thin - a MITRE description and third-party writeups, with no vendor advisory or fixed version linked - so treat the affected-version range as unestablished.

Who can reach it

Authenticated OpenStack user able to create an image or set an image location, on a deployment where Glance is configured with the VMware datastore backend. Requires outbound network from the Glance service to the attacker's host.

What to do

No fixed version is named in the record. Check the OpenStack security advisories for glance_store before planning an upgrade. In the meantime, restrict who may set image locations (show_multiple_locations / the location-setting policy), and egress-filter the Glance service so it can only reach the vCenter datastore endpoints it is configured for. Applying a fix, once published, is a package update plus a Glance API restart.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.