Glance

Vendor:

First CVE: Mar 22, 2013 · Active for 13 years

12
Total CVEs
More Total CVEs than 90% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Glance over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 22, 2013
13 years ago
Most Recent CVE
Mar 31, 2026
115 days ago

CVE Severity & Scoring

Glance12 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local2 (16.7%)
Network6 (50.0%)
Unknown4 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (66.7%)
High0 (0.0%)
Unknown4 (33.3%)
User Interaction
None5 (41.7%)
Unknown4 (33.3%)
Required3 (25.0%)
Privileges Required
Low5 (41.7%)
High0 (0.0%)
None3 (25.0%)
Unknown4 (33.3%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL val
Mar 31, 20267.126NONO
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplyi
Jul 5, 20246.523NONO
An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v
Mar 21, 20175.822NONO
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before
Jan 26, 20235.721NONO
The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.
Mar 29, 20175.520NONO
The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which
Oct 7, 20167.520NONO
A vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2 `/images` API POST method for authenticated users, resultin
Jul 31, 20186.518NONO
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using th
Mar 6, 20232.815NONO
OpenStack Glance before 2015.1.1 (kilo) allows remote authenticated users to cause a denial of service (disk consumption) by repeatedly using the import task flow API to create ima
Aug 14, 20154.014NONO
The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a c
Aug 19, 20153.513NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Glance

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
v113.51.4%00
31.0.017.10.3%00
27.0.016.50.8%00
2015.1.113.51.5%00
2015.1.013.51.5%00
2013.213.53.1%00
12.0.017.53.1%00
11.0.117.53.1%00
11.0.015.51.2%00