Glance
Vendor:
First CVE: Mar 22, 2013 · Active for 13 years
12
Total CVEs
More Total CVEs than 90% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Glance over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 22, 2013
13 years ago
Most Recent CVE
Mar 31, 2026
115 days ago
CVE Severity & Scoring
Glance12 CVEs
33%
50%
17%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local2 (16.7%)
Network6 (50.0%)
Unknown4 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (66.7%)
High0 (0.0%)
Unknown4 (33.3%)
User Interaction
None5 (41.7%)
Unknown4 (33.3%)
Required3 (25.0%)
Privileges Required
Low5 (41.7%)
High0 (0.0%)
None3 (25.0%)
Unknown4 (33.3%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34881HIGH OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL val | Mar 31, 2026 | 7.1 | 26 | NO | NO |
CVE-2024-32498MEDIUM An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplyi | Jul 5, 2024 | 6.5 | 23 | NO | NO |
CVE-2017-7200MEDIUM An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v | Mar 21, 2017 | 5.8 | 22 | NO | NO |
CVE-2022-47951MEDIUM An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before | Jan 26, 2023 | 5.7 | 21 | NO | NO |
CVE-2015-8234MEDIUM The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision. | Mar 29, 2017 | 5.5 | 20 | NO | NO |
CVE-2015-5162HIGH The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which | Oct 7, 2016 | 7.5 | 20 | NO | NO |
CVE-2016-8611MEDIUM A vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2 `/images` API POST method for authenticated users, resultin | Jul 31, 2018 | 6.5 | 18 | NO | NO |
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using th | Mar 6, 2023 | 2.8 | 15 | NO | NO |
CVE-2015-3289MEDIUM OpenStack Glance before 2015.1.1 (kilo) allows remote authenticated users to cause a denial of service (disk consumption) by repeatedly using the import task flow API to create ima | Aug 14, 2015 | 4.0 | 14 | NO | NO |
The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a c | Aug 19, 2015 | 3.5 | 13 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Glance
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| v1 | 1 | 3.5 | 1.4% | 0 | 0 |
| 31.0.0 | 1 | 7.1 | 0.3% | 0 | 0 |
| 27.0.0 | 1 | 6.5 | 0.8% | 0 | 0 |
| 2015.1.1 | 1 | 3.5 | 1.5% | 0 | 0 |
| 2015.1.0 | 1 | 3.5 | 1.5% | 0 | 0 |
| 2013.2 | 1 | 3.5 | 3.1% | 0 | 0 |
| 12.0.0 | 1 | 7.5 | 3.1% | 0 | 0 |
| 11.0.1 | 1 | 7.5 | 3.1% | 0 | 0 |
| 11.0.0 | 1 | 5.5 | 1.2% | 0 | 0 |