CVE-2026-51773

An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destination host before attaching sensitive authentication headers.

  • Published Sep 25, 2026
  • CVSS 8.1 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)

CVE-2026-51773 at the National Vulnerability Database