Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3664
  • PyPI/glances
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config 19 Aug
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-3665
  • PyPI/glances
Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925) 19 Aug
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-3666
  • PyPI/glances
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection 19 Aug
  • Fix available
  • Severity - 8.8 (High)
PYSEC-2026-3667
  • PyPI/glances
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard 19 Aug
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-3668
  • PyPI/glances
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction 19 Aug
  • Fix available
  • Severity - 8.8 (High)
GHSA-4h34-v6r8-mmjc
  • PyPI/glances
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config 17 Aug
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-59fj-m2j6-hcxh
  • PyPI/glances
Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925) 17 Aug
  • Fix available
  • Severity - 7.1 (High)
GHSA-73wf-9vmv-5pv9
  • PyPI/glances
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection 17 Aug
  • Fix available
  • Severity - 8.8 (High)
GHSA-fp27-88fp-2phg
  • PyPI/glances
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard 17 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-qcpp-8x79-hhp3
  • PyPI/glances
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction 17 Aug
  • Fix available
  • Severity - 8.8 (High)
PYSEC-2026-2494
  • PyPI/glances
Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration 13 Jul
  • Fix available
  • Severity - 7.8 (High)
PYSEC-2026-2498
  • PyPI/glances
Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack 13 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-2495
  • PyPI/glances
Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533) 13 Jul
  • Fix available
  • Severity - 7.4 (High)
PYSEC-2026-2496
  • PyPI/glances
Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code Execution 13 Jul
  • Fix available
  • Severity - 7.8 (High)
PYSEC-2026-2497
  • PyPI/glances
Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py 13 Jul
  • Fix available
  • Severity - 7.8 (High)
PYSEC-2026-343
  • PyPI/glances
Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist` 29 Jun
  • Fix available
  • Severity - 9.1 (Critical)