glances vulnerabilities
CVEs whose affected-version data names the glances package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
24 CVEsRSS
CVE-2026-68517Medium· 6.5Glances is an open-source system cross-platform monitoring tool
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list conta…
CVE-2026-62982High· 8.8Glances is an open-source system cross-platform monitoring tool
Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in glances/actions.py skips nested list and dictionary strings such as process cmdline values, allowing pipe characters to…
CVE-2026-68519HighGlances is an open-source system cross-platform monitoring tool
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, GlancesActions.run() in glances/actions.py ignores --disable-config-exec for on-alert action commands and invokes secure_popen() with shell operators enable…
CVE-2026-68520Medium· 5.3Glances is an open-source system cross-platform monitoring tool
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py checks only option names and exposes public_username and credentials embedded in public_api values through unauthentic…
CVE-2026-68518HighGlances is an open-source system cross-platform monitoring tool
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing adjacent unescaped Mustache variables…
CVE-2026-53925High· 7.8Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration
Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration
CVE-2026-46606High· 7.8Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py
Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py
CVE-2026-46607High· 7.8Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code Execution
Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code Execution
CVE-2026-46608High· 7.4Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)
Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)
CVE-2026-46611Medium· 5.3Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack
Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack
CVE-2026-35588Medium· 6.3Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values
Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values
CVE-2026-34839Medium· 6.5Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
CVE-2026-35587High· 8.8Glances has SSRF in IP Plugin via public_api leading to credential leakage
Glances has SSRF in IP Plugin via public_api leading to credential leakage
CVE-2026-33641High· 7.8PoCGlances Vulnerable to Command Injection via Dynamic Configuration Values
Glances Vulnerable to Command Injection via Dynamic Configuration Values
CVE-2026-33533HighGlances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard
Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard
CVE-2026-32596HighPoCGlances exposes the REST API without authentication
Glances exposes the REST API without authentication
CVE-2026-32634High· 8.1Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers
Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers
CVE-2026-32608High· 7.0Glances has a Command Injection via Process Names in Action Command Templates
Glances has a Command Injection via Process Names in Action Command Templates
CVE-2026-32632Medium· 5.9Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding
Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding
CVE-2026-32609High· 7.5Glances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP Credentials
Glances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP Credentials
CVE-2026-32610High· 8.1Glances's Default CORS Configuration Allows Cross-Origin Credential Theft
Glances's Default CORS Configuration Allows Cross-Origin Credential Theft
CVE-2026-32611High· 7.0Glances has a SQL Injection in DuckDB Export via Unparameterized DDL Statements
Glances has a SQL Injection in DuckDB Export via Unparameterized DDL Statements
CVE-2026-30930HighGlances has SQL Injection via Process Names in TimescaleDB Export
Glances has SQL Injection via Process Names in TimescaleDB Export
CVE-2026-30928HighPoCGlances Exposes Unauthenticated Configuration Secrets
Glances Exposes Unauthenticated Configuration Secrets