Database/Control plane, storage & DevOps
OpenStack glance_store: VMware datastore driver sends authentication headers to an attacker-supplied image location host
Impact
_retry_request in the VMware datastore driver does not validate the destination host before attaching authentication headers, so an image location URI pointing at an external server makes Glance deliver its datastore credentials there. An authenticated user who can set an image location gets the vCenter datastore credentials Glance holds, plus a request-forgery primitive from Glance's network position inside the management network. For an operator running OpenStack as the fleet's control plane, that is a credential leak into the virtualization layer where the GPU instances are created. The available record is thin - a MITRE description and third-party writeups, with no vendor advisory or fixed version linked - so treat the affected-version range as unestablished.
Who can reach it
Authenticated OpenStack user able to create an image or set an image location, on a deployment where Glance is configured with the VMware datastore backend. Requires outbound network from the Glance service to the attacker's host.
What to do
No fixed version is named in the record. Check the OpenStack security advisories for glance_store before planning an upgrade. In the meantime, restrict who may set image locations (show_multiple_locations / the location-setting policy), and egress-filter the Glance service so it can only reach the vCenter datastore endpoints it is configured for. Applying a fix, once published, is a package update plus a Glance API restart.
References
Related entries
- Ceph RGW: unsigned x-amz-* headers on presigned URLs are honored, letting a URL holder escalate privilegesCVE-2026-54330 · Ceph Object Gateway (RGW SigV4 presigned-URL header validation)High
- Apache Airflow Git provider: SSH host-key verification disabled by default when cloning DAG bundlesCVE-2026-58065 · Apache Airflow Git provider (apache-airflow-providers-git, git-over-SSH host key checking)High
- Apache Airflow FAB provider: a DAG named 'DAGs' collides with the global all-DAGs permission and escalates privilegesCVE-2026-59245 · Apache Airflow FAB auth manager (apache-airflow-providers-fab, resource_name collision)High
- Linux MACsec (replay protection at XPN lower-PN wrap): MACsec replay protection fails at the extended-packet-numberCVE-2026-63925 · Linux MACsec (replay protection at XPN lower-PN wrap)High
- Atlantis: workspace names escape the working directory into os.RemoveAll and os.MkdirAllCVE-2026-64679 · Atlantis (workspace path handling in atlantis.yaml and /api/plan)High
- Dell PowerStore T SDNAS: unauthenticated NFS/RPC buffer overflow allows command execution on the arrayCVE-2026-70415 · Dell PowerStore T SDNAS (NFS/RPC service)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.