An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker...

zetlyn/cve-ghsa vulnerability ghsa GHSA-p93m-62q2-q66v cve CVE-2026-51773 known 2026-09-25

https://github.com/advisories/GHSA-p93m-62q2-q66v

Properties

cvss8.1
receipt
Source
GitHub advisories
Said since
2026-09-26 15:00 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source

This source has not kept a receipt for this claim yet. The next update that reads it will.

cweCWE-918
receipt
Source
GitHub advisories
Said since
2026-09-26 15:00 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source

This source has not kept a receipt for this claim yet. The next update that reads it will.

severityhigh
From 7.0 to 8.9.
receipt
Source
GitHub advisories
Said since
2026-09-26 15:00 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source

This source has not kept a receipt for this claim yet. The next update that reads it will.

Text

An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker... An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destination host before attaching sensitive authentication headers.