CVE-2026-51773

NONE
Updated Sep 25, 2026
VMWARE
Parameter Value
Vendor VMWARE
Public PoC No

An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destination host before attaching sensitive authentication headers.

Vulnerable Products

n/a:n/a