Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Glances — Vulnerabilities & Security Advisories 26

All 26 CVE vulnerabilities found in Glances, with AI-generated Chinese analysis, references, and POCs.

This page covers the vulnerability aggregation report for the open-source system monitoring tool Glances, focusing on common weakness classifications within the software ecosystem. It collects a comprehensive list of identified security flaws, including remote code execution risks, cross-site scripting issues, and privilege escalation vulnerabilities found in various releases of the product. The data spans from the initial public release of Glances through to the most recent patches issued by the development team, ensuring that both legacy and current versions are accounted for in the analysis. Here, you can track the vendor's advisory history to understand how quickly patches are released after disclosure, get a deeper understanding of specific weakness classes that frequently affect monitoring tools, and look up the full vulnerability history of Glances to assess long-term maintenance trends. This resource is designed to help system administrators, security researchers, and DevOps engineers evaluate the security posture of their monitoring infrastructure. By analyzing the chronological progression of these issues, users can identify patterns in coding errors or configuration mistakes that may persist across different versions. The page serves as a central reference point for determining whether specific systems running Glances are at risk and provides context for applying necessary updates. It does not provide workarounds or mitigation strategies directly but instead offers the raw data needed to make informed security decisions regarding the deployment and maintenance of this popular resource monitoring utility.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-68519 Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925) CWE-78 7.1 High 2026-08-17
CVE-2026-62982 Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection CWE-78 8.8 High 2026-08-17
CVE-2026-68520 Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config CWE-200 5.3 Medium 2026-08-17
CVE-2026-68517 Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard CWE-942 6.5 Medium 2026-08-17
CVE-2026-68518 Glances: Command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction CWE-78 8.8 High 2026-08-17
CVE-2026-46608 Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533) CWE-183 7.4 High 2026-06-25
CVE-2026-46607 Glances: Insecure Pickle Deserialization in Version Cache Leads to Arbitrary Code Execution CWE-502 7.8 High 2026-06-25
CVE-2026-53925 Glances: Arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration CWE-22 7.8 High 2026-06-25
CVE-2026-46606 Glances: Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py CWE-78 7.8 High 2026-06-25
CVE-2026-46611 Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack CWE-346 5.3 Medium 2026-06-25
CVE-2026-35588 Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values CWE-89 6.3 Medium 2026-04-20
CVE-2026-35587 Glances IP Plugin has SSRF via public_api that leads to credential leakage CWE-918 9.8AI Critical AI 2026-04-20
CVE-2026-34839 Glances Vulnerable to Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS CWE-200 6.5AI Medium AI 2026-04-20
CVE-2026-33641 Glances Vulnerable to Command Injection via Dynamic Configuration Values CWE-78 7.8 High 2026-04-02
CVE-2026-33533 Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard CWE-942 8.1AI High AI 2026-04-02
CVE-2026-32634 Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers CWE-346 8.1 High 2026-03-18
CVE-2026-32633 Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist` CWE-200 9.1 Critical 2026-03-18
CVE-2026-32632 Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding CWE-346 5.9 Medium 2026-03-18
CVE-2026-32611 Glances has a SQL Injection in DuckDB Export via Unparameterized DDL Statements CWE-89 7.0 High 2026-03-18
CVE-2026-32610 Glances's Default CORS Configuration Allows Cross-Origin Credential Theft CWE-942 8.1 High 2026-03-18
CVE-2026-32609 Glances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP Credentials CWE-200 7.5 High 2026-03-18
CVE-2026-32608 Glances has a Command Injection via Process Names in Action Command Templates CWE-78 7.0 High 2026-03-18
CVE-2026-32596 Glances exposes the REST API without authentication CWE-200 9.1 - 2026-03-18
CVE-2026-30930 Glances has SQL Injection via Process Names in TimescaleDB Export CWE-89 9.8AI Critical AI 2026-03-10
CVE-2026-30928 Glances Exposes Unauthenticated Configuration Secrets CWE-200 9.1AI Critical AI 2026-03-10
CVE-2021-23418 XML External Entity (XXE) Injection 6.3 Medium 2021-07-29

All 26 known CVE vulnerabilities affecting Glances with full Chinese analysis, references, and POCs where available.