VDB
Sign up
—

PYSEC-2026-817

OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability

Quick fix

PYSEC-2026-817 — glance: upgrade to the fixed version with the command below.

pip install --upgrade 'glance>=2013.2.4'

Details

The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/glance
Introduced in: 2013.2Fixed in: 2013.2.4
Fixpip install --upgrade 'glance>=2013.2.4'

References