© 2025-2026 PySpect
First version without a known vulnerability: 4.5.6
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config
Fixed in: 4.5.6
Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)
Fixed in: 4.5.6
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
Fixed in: 4.5.6
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
Fixed in: 4.5.6
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
Fixed in: 4.5.6
Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration
Fixed in: 4.5.5
Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack
Fixed in: 4.5.5
Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)
Fixed in: 4.5.5
Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code Execution
Fixed in: 4.5.5
Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py
Fixed in: 4.5.5
Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values
Fixed in: 4.5.4
Glances has SSRF in IP Plugin via public_api leading to credential leakage
Fixed in: 4.5.4
Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
Fixed in: 4.5.4
Glances Vulnerable to Command Injection via Dynamic Configuration Values
Fixed in: 4.5.3
Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard
Fixed in: 4.5.3
Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers
Fixed in: 4.5.2
Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`
Fixed in: 4.5.2
Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding
Fixed in: 4.5.2
Glances has a SQL Injection in DuckDB Export via Unparameterized DDL Statements
Fixed in: 4.5.2
Glances's Default CORS Configuration Allows Cross-Origin Credential Theft
Fixed in: 4.5.2
Glances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP Credentials
Fixed in: 4.5.2
Glances has a Command Injection via Process Names in Action Command Templates
Fixed in: 4.5.2
Glances exposes the REST API without authentication
Fixed in: 4.5.2
Glances has SQL Injection via Process Names in TimescaleDB Export
Fixed in: 4.5.1
Glances Exposes Unauthenticated Configuration Secrets
Fixed in: 4.5.1
XML External Entity Reference in Glances
Fixed in: 3.2.1, 85d5a6b4af31fcf785d5a61086cbbd166b40b07a, 9d6051be4a42f692392049fdbfc85d5dfa458b32, 4b87e979afdc06d98ed1b48da31e69eaa3a9fb94