{"id":"CVE-2026-35588","aliases":["GHSA-grp3-h8m8-45p7","PYSEC-2026-2177"],"title":"Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values","summary":"Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values","severity":"medium","cvss":6.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L","vendor":"glances","product":"glances","ecosystem":"pip","affected":["glances < 4.5.4"],"patched":["glances 4.5.4"],"published":"2026-04-21","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-grp3-h8m8-45p7","references":[{"url":"https://github.com/nicolargo/glances/security/advisories/GHSA-grp3-h8m8-45p7"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35588"},{"url":"https://github.com/nicolargo/glances/commit/d339181f03a14bb15506307e9d58f876e23d8160"},{"url":"https://github.com/nicolargo/glances/commit/e41b665576f9fd5374e3152078726cc59a01e48c"},{"url":"https://github.com/nicolargo/glances"}],"tags":["osv","pip"],"epss":0.00212,"epssPercentile":0.11728,"ingestedAt":"2026-07-13T18:57:58.564Z","slug":"CVE-2026-35588","body":"## Overview\n\n## Summary\n\nThe Cassandra export module (`glances/exports/glances_cassandra/__init__.py`) interpolates `keyspace`, `table`, and `replication_factor` configuration values directly into CQL statements without validation. A user with write access to `glances.conf` can redirect all monitoring data to an attacker-controlled Cassandra keyspace.\n\n## Vulnerable Code\n\n```python\n# Line 80\nf\"CREATE KEYSPACE {self.keyspace} WITH \"\nf\"replication = {{ 'class': 'SimpleStrategy', 'replication_factor': '{self.replication_factor}' }}\"\n\n# Line 94\nf\"CREATE TABLE {self.table} (plugin text, time timeuuid, stat map<text,float>, PRIMARY KEY (plugin, time)) WITH CLUSTERING ORDER BY (time DESC)\"\n\n# Line 112\nstmt = f\"INSERT INTO {self.table} (plugin, time, stat) VALUES (?, ?, ?)\"\n```\n\n## Steps to Reproduce\n\n1. Configure `glances.conf` with malicious `table` value:\n```ini\n[cassandra]\nhost = 127.0.0.1\nport = 9042\nkeyspace = glances\ntable = attacker_ks.captured_stats\n```\n2. Create attacker keyspace in Cassandra\n3. Run `glances --export cassandra`\n4. All monitoring data is written to `attacker_ks.captured_stats` instead of the legitimate table\n\n**Confirmed output:**\n```\nINSERT stmt: INSERT INTO attacker_ks.captured_stats (plugin, time, stat) VALUES (?, ?, ?)\nLegitimate table row count: 0\nAttacker table row count: 1\n[CONFIRMED] plugin=cpu, stat={'user': 50.0}\n```\n\n## Impact\n\nAll exported monitoring data (CPU, memory, network, disk I/O) is silently redirected to an attacker-controlled Cassandra keyspace — both data exfiltration and data loss.\n\n## Proposed Fix\n\n```python\nimport re\n\ndef _validate_cql_identifier(name: str) -> str:\n    if not re.match(r'^[a-zA-Z_][a-zA-Z0-9_.]*$', name):\n        raise ValueError(f\"Invalid CQL identifier: {name!r}\")\n    return name\n\n# In __init__(): validate before use\nself.keyspace = _validate_cql_identifier(self.keyspace)\nself.table = _validate_cql_identifier(self.table)\n```\n\n![PoC](https://raw.githubusercontent.com/n0z0/cve-evidence/main/2026-04/20260403_004238_glances_cassandra_cql_injection_poc.png)\n\n## Affected packages\n\n- `glances < 4.5.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `glances 4.5.4`","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}