An issue in the VMware datastore driver of OpenStack...
High severity
Unreviewed
Published
Sep 25, 2026
to the GitHub Advisory Database
•
Updated Sep 25, 2026
Description
Published by the National Vulnerability Database
Sep 25, 2026
Published to the GitHub Advisory Database
Sep 25, 2026
Last updated
Sep 25, 2026
An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destination host before attaching sensitive authentication headers.
References