{"id":"CVE-2026-34839","aliases":["GHSA-gfc2-9qmw-w7vh","PYSEC-2026-2175"],"title":"Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS","summary":"Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","vendor":"glances","product":"glances","ecosystem":"pip","affected":["glances < 4.5.4"],"patched":["glances 4.5.4"],"published":"2026-04-21","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-gfc2-9qmw-w7vh","references":[{"url":"https://github.com/nicolargo/glances/security/advisories/GHSA-gfc2-9qmw-w7vh"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34839"},{"url":"https://github.com/nicolargo/glances/commit/fdfb977b1d91b5e410bc06c4e19f8bedb0005ce9"},{"url":"https://github.com/nicolargo/glances"}],"tags":["osv","pip"],"epss":0.00408,"epssPercentile":0.34712,"ingestedAt":"2026-07-13T18:57:58.331Z","slug":"CVE-2026-34839","body":"## Overview\n\n### Summary\nThe Glances web server exposes a REST API (`/api/4/*`) that is accessible without authentication and allows cross-origin requests from any origin due to a permissive CORS policy (`Access-Control-Allow-Origin: *`).\n\nThis allows a malicious website to read sensitive system information from a running Glances instance in the victim’s browser, leading to cross-origin data exfiltration.\n\nWhile a previous advisory exists for XML-RPC CORS issues, this report demonstrates that the REST API (`/api/4/*`) is also affected and exposes significantly more sensitive data.\n\n### Details\nWhen Glances is started in web mode (e.g., `glances -w -B 0.0.0.0`), it exposes a REST API endpoint at:\nhttp://<host>:61208/api/4/all\nThe server responds with:\nAccess-Control-Allow-Origin: *\n\nThis allows any origin to perform cross-origin requests and read responses.\n\nThe `/api/4/all` endpoint returns extensive system information, including:\n- Process list (`processlist`)\n- System details (hostname, OS, CPU info)\n- Memory and disk usage\n- Network interfaces and IP address\n- Running services and metrics\nBecause no authentication is required by default, this data is accessible to any web page.\n\n### PoC\n1. Start Glances:\nglances -w -B 0.0.0.0\n\n2. Create a malicious HTML file:\n\n```\n<!DOCTYPE html>\n<html>\n<body>\n<script>\nfetch(\"http://<victim-ip>:61208/api/4/all\")\n  .then(r => r.json())\n  .then(data => {\n    console.log(\"DATA:\", data);\n  });\n</script>\n</body>\n</html>\n```\n2. Open the file in a browser while Glances is running.\n3. Observe that the browser successfully retrieves sensitive system information from the API.\nThis works cross-origin (e.g., from file:// or attacker-controlled domains).\n\n### Impact\nA remote attacker can host a malicious website that, when visited by a victim running Glances, can:\n\n- Read sensitive system information\n- Enumerate running processes\n- Identify network configuration and IP addresses\n- Fingerprint the host system\n\nThis requires no authentication and no user interaction beyond visiting a web page. This represents a cross-origin information disclosure vulnerability and can aid further attacks such as reconnaissance or targeted exploitation.\n\n## Affected packages\n\n- `glances < 4.5.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `glances 4.5.4`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}