{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/openstack-foundation/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-63770"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Glance (\u003c= 0.8.5)"],"_cs_severities":["high"],"_cs_tags":["credential-access","defense-evasion","vulnerability","web-application","proxy","brute-force"],"_cs_type":"advisory","_cs_vendors":["OpenStack Foundation"],"content_html":"\u003cp\u003eUnauthenticated attackers can exploit CVE-2026-63770, an IP address spoofing vulnerability in Glance through version 0.8.5, to bypass brute-force lockout protections. This flaw resides in the authentication handler and is exploitable when the server's proxied option is enabled. Attackers leverage the X-Forwarded-For HTTP request header, manipulating its leftmost value with arbitrary inputs to make each subsequent login attempt appear to originate from a new, distinct IP address. This technique circumvents per-IP failed-login counters, preventing the activation of lockout thresholds and allowing for an unlimited number of credential guessing attempts against the authentication endpoint. The vulnerability effectively nullifies a critical security control designed to prevent credential stuffing and brute-force attacks against Glance, an OpenStack image service, making it significantly easier for adversaries to compromise user accounts.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies a vulnerable Glance instance (version 0.8.5 or earlier) that has the server's proxied option enabled.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts HTTP POST requests targeting the Glance authentication endpoint, typically \u003ccode\u003e/auth\u003c/code\u003e or a similar path.\u003c/li\u003e\n\u003cli\u003eIn each authentication request, the attacker includes an \u003ccode\u003eX-Forwarded-For\u003c/code\u003e HTTP header.\u003c/li\u003e\n\u003cli\u003eFor every subsequent login attempt, the attacker modifies the leftmost IP address value within the \u003ccode\u003eX-Forwarded-For\u003c/code\u003e header to an arbitrary, distinct value.\u003c/li\u003e\n\u003cli\u003eAlong with the manipulated \u003ccode\u003eX-Forwarded-For\u003c/code\u003e header, the attacker submits a guessed username and password combination.\u003c/li\u003e\n\u003cli\u003eThe Glance authentication handler, when configured in a proxied environment, incorrectly interprets each unique \u003ccode\u003eX-Forwarded-For\u003c/code\u003e value as a distinct originating IP address.\u003c/li\u003e\n\u003cli\u003eThis manipulation prevents the per-IP failed-login counter from incrementing beyond the lockout threshold for any single perceived IP, thereby bypassing brute-force lockout mechanisms.\u003c/li\u003e\n\u003cli\u003eThe attacker can continue to guess credentials indefinitely against the authentication endpoint until a valid credential pair is discovered, leading to unauthorized access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-63770 allows attackers to perform unlimited credential guessing against Glance authentication endpoints, effectively bypassing built-in brute-force protection mechanisms. This can lead to unauthorized access to the Glance application, which is a key component of OpenStack for managing virtual machine images. Compromise of Glance could grant attackers control over the virtual machine image repository, allowing them to inject malicious images, tamper with existing ones, or gain a foothold into the broader OpenStack environment, potentially leading to unauthorized data access, service disruption, or further system compromise. While the NVD entry does not specify observed exploitation or victim count, the ability to defeat brute-force protections for a critical component like an image service poses a significant risk for organizations using vulnerable versions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-63770 by upgrading Glance to a version greater than 0.8.5 immediately.\u003c/li\u003e\n\u003cli\u003eReview web server, load balancer, and proxy configurations to ensure \u003ccode\u003eX-Forwarded-For\u003c/code\u003e headers are correctly handled, sanitized, and validated, especially when Glance's proxied option is enabled.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect suspicious \u003ccode\u003eX-Forwarded-For\u003c/code\u003e header manipulation attempts against authentication endpoints.\u003c/li\u003e\n\u003cli\u003eImplement strong authentication policies, such as multi-factor authentication (MFA), for all user accounts accessing Glance and other OpenStack components to mitigate the impact of compromised credentials.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T19:26:04Z","date_published":"2026-07-20T19:26:04Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-63770-glance-spoofing/","summary":"A vulnerability in Glance through version 0.8.5 allows unauthenticated attackers to bypass brute-force lockout protections by manipulating the X-Forwarded-For HTTP header with arbitrary values, making each login attempt appear to originate from a distinct IP address when the server's proxied option is enabled, thereby enabling unlimited credential guessing against the authentication endpoint.","title":"CVE-2026-63770: Glance IP Address Spoofing Vulnerability Bypasses Brute-Force Lockout","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-63770-glance-spoofing/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenStack Foundation","version":"https://jsonfeed.org/version/1.1"}