CVE-2026-51772

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance. When the show_multiple_locations configuration option is enabled in glance-api.conf, an authenticated attacker can manipulate the locations attribute of an image in the queued state by sending a crafted HTTP PATCH request

Published 2026-09-25. Last modified 2026-09-30.