VDB
Sign up
—

PYSEC-2026-815

OpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme

Quick fix

PYSEC-2026-815 — glance: upgrade to the fixed version with the command below.

pip install --upgrade 'glance>=11.0.0a0'

Details

The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users to read or delete arbitrary files via a full pathname in a `filesystem://` URL in the image location property. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9493.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/glance
Introduced in: 0Fixed in: 11.0.0a0
Fixpip install --upgrade 'glance>=11.0.0a0'

References