CVE-2026-63770: Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass

Published Jul 20, 2026
·
Updated

Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthenticated attackers to bypass brute-force lockout protections by supplying arbitrary values in the X-Forwarded-For request header when the server proxied option is enabled. Attackers can manipulate the leftmost value of the X-Forwarded-For header to make each login attempt appear to originate from a distinct IP address, preventing the per-IP failed-login counter from reaching the lockout threshold and enabling unlimited credential guessing against the authentication endpoint.

Affected Software

1 affected component
Openstack Glance=0.8.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Glance to a version that resolves this vulnerability.

    Fixed in 0.8.5
  2. Configuration

    Disable the server proxied option so the authentication handler does not trust arbitrary X-Forwarded-For values from requests, preventing bypass of brute-force lockout protections.

    Glance authentication handler (proxy/X-Forwarded-For handling) server proxied option = disabled

Event History

Jul 20, 2026
CVE Published
via MITRE·07:02 PM
Data Sourced
via MITRE·07:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness
Feb 8, 58521
Event
via NVD·09:52 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-63770?

The severity of CVE-2026-63770 is rated as high with a CVSS score of 7.5.

2

How do I fix CVE-2026-63770?

To fix CVE-2026-63770, upgrade to a version of OpenStack Glance that addresses this vulnerability.

3

What types of attacks does CVE-2026-63770 allow?

CVE-2026-63770 allows unauthenticated attackers to bypass brute-force lockout protections by spoofing the IP address.

4

What software is affected by CVE-2026-63770?

CVE-2026-63770 affects OpenStack Glance version 0.8.5.

5

What is the impact of exploiting CVE-2026-63770?

Exploiting CVE-2026-63770 can allow attackers to successfully authenticate by evading brute-force protection mechanisms.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203