Synopsis
The remote Debian host is missing one or more security-related updates.
Description
The remote Debian 12 host has packages installed that are affected by multiple vulnerabilities as referenced in the dla-4800 advisory.
------------------------------------------------------------------------- Debian LTS Advisory DLA-4800-1 [email protected] https://www.debian.org/lts/security/ Carlos Henrique Lima Melara September 29, 2026 https://wiki.debian.org/LTS
-------------------------------------------------------------------------
Package : glance Version : 2:25.1.0-2+deb12u5 CVE ID : CVE-2026-71196 CVE-2026-71197 CVE-2026-71198 CVE-2026-77648 Debian Bug : 1144212 1146594
Multiple vulnerabilities were discovered in Glance, OpenStack's image storage service.
CVE-2026-71196, CVE-2026-71197 and CVE-2026-71198 / OSSA-2026-038
Three related Server-Side Request Forgery (SSRF) vulnerabilities in the web-download import method and HTTP image location APIs: insecure default URI filtering permitted an authenticated user to fetch arbitrary internal URLs, including cloud metadata endpoints; the URI validator did not perform DNS resolution before applying host filters, allowing bypass via attacker-controlled domains and DNS rebinding attacks; and when the HTTP store was enabled, the image location API lacked host filtering entirely, storing fetched content as downloadable image data, converting blind SSRF into full-read exfiltration. An unbounded fetch when the source omitted Content-Length could also fill the disk (image_size_cap is now honored).
CVE-2026-77648 / OSSN-0105
The legacy (deprecated) /v2/tasks API accepted type=import tasks which bypassed the import URI filtering (host, port and path restrictions) enforced by the modern image import, allowing an admin to fetch internal URLs from the Glance service network (SSRF). Legacy import URIs are now validated the same way as modern import.
For Debian 12 bookworm, these problems have been fixed in version 2:25.1.0-2+deb12u5.
We recommend that you upgrade your glance packages.
For the detailed security status of glance please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/glance
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Attachment:
signature.asc Description: PGP signature
Tenable has extracted the preceding description block directly from the Debian security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Upgrade the glance packages.
Plugin Details
File Name: debian_DLA-4800.nasl
Agent: unix
Supported Sensors: Nessus Agent, Continuous Assessment, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:H/Au:M/C:P/I:N/A:N
Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Threat Vector: CVSS:4.0/E:U
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Vulnerability Information
CPE: cpe:/o:debian:debian_linux:12.0, p-cpe:/a:debian:debian_linux:glance-api, p-cpe:/a:debian:debian_linux:glance-common, p-cpe:/a:debian:debian_linux:glance-doc, p-cpe:/a:debian:debian_linux:glance, p-cpe:/a:debian:debian_linux:python3-glance
Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l
Exploit Ease: No known exploits are available
Patch Publication Date: 9/29/2026
Vulnerability Publication Date: 8/20/2026