{"id":"PYSEC-2026-812","summary":"OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service","details":"OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9623.","aliases":["CVE-2015-5286","GHSA-gvjg-r9fv-7qx9"],"modified":"2026-07-09T13:45:12.265033501Z","published":"2026-07-06T08:03:25.587152Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-5286"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2015:1897"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2015-5286"},{"type":"WEB","url":"https://bugs.launchpad.net/bugs/1498163"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1267516"},{"type":"PACKAGE","url":"https://opendev.org/openstack/glance"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2015-1897.html"},{"type":"WEB","url":"https://security.openstack.org/ossa/OSSA-2015-020.html"},{"type":"WEB","url":"https://web.archive.org/web/20200228024859/http://www.securityfocus.com/bid/76943"},{"type":"PACKAGE","url":"https://pypi.org/project/glance"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gvjg-r9fv-7qx9"}],"affected":[{"package":{"name":"glance","ecosystem":"PyPI","purl":"pkg:pypi/glance"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2014.2.4"},{"introduced":"2015.1.0"},{"fixed":"2015.1.2"}]}],"versions":["15.0.2","17.0.1","18.0.0","18.0.0.0b1","18.0.0.0rc1","18.0.1","19.0.0","19.0.0.0b1","19.0.0.0rc1","19.0.0.0rc2","19.0.1","19.0.2","19.0.3","19.0.4","20.0.0","20.0.0.0b1","20.0.0.0b2","20.0.0.0b3","20.0.0.0rc1","20.0.0.0rc2","20.0.1","20.1.0","20.2.0","21.0.0","21.0.0.0b1","21.0.0.0b2","21.0.0.0rc1","21.0.0.0rc2","21.1.0","22.0.0","22.0.0.0b2","22.0.0.0b3","22.0.0.0rc1","22.1.0","22.1.1","23.0.0","23.0.0.0b2","23.0.0.0b3","23.0.0.0rc1","23.0.0.0rc2","23.1.0","24.0.0","24.0.0.0rc1","24.1.0","24.2.0","24.2.1","25.0.0","25.0.0.0b2","25.0.0.0b3","25.0.0.0rc1","25.1.0","26.0.0","26.0.0.0b2","26.0.0.0b3","26.0.0.0rc1","26.1.0","27.0.0","27.0.0.0b1","27.0.0.0b2","27.0.0.0rc1","27.1.0","27.1.1","28.0.0","28.0.0.0b2","28.0.0.0rc1","28.0.1","28.1.0","28.2.0","29.0.0","29.0.0.0b1","29.0.0.0b2","29.0.0.0b3","29.0.0.0rc1","29.1.0","29.2.0","29.2.1","30.0.0","30.0.0.0b2","30.0.0.0rc1","30.1.0","30.2.0","31.0.0","31.0.0.0b2","31.0.0.0rc1","31.1.0","32.0.0","32.0.0.0b2","32.0.0.0rc1","32.0.0.0rc2","33.0.0.0b2"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/glance/PYSEC-2026-812.yaml"}}],"schema_version":"1.7.5"}