<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T23:30:36.481362+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07194</id>
    <title>bdu:2026-07194</title>
    <updated>2026-10-06T23:30:36.540266+00:00</updated>
    <content>bdu:2026-07194</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07194"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-glances-cve-2026-32634</id>
    <title>BREW-glances-CVE-2026-32634 — Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers</title>
    <updated>2026-10-06T23:30:36.540306+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: glances</p>
<p>Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised server name and the discovered IP address for dynamic servers, but later builds connection URIs from the untrusted advertised name instead of the discovered IP. When a dynamic server reports itself as protected, Glances also uses that same untrusted name as the lookup key for saved passwords and the global `[passwords] default` credential. An attacker on the same local network can advertise a fake Glances service over Zeroconf and cause the browser to automatically send a reusable Glances authentication secret to an attacker-controlled host. This affects the background polling path and the REST/WebUI click-through path in Central Browser mode. Version 4.5.2 fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-glances-cve-2026-32634"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-276501</id>
    <title>EUVD-2026-276501</title>
    <updated>2026-10-06T23:30:36.540345+00:00</updated>
    <content>EUVD-2026-276501</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-276501"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32634</id>
    <title>fkie_cve-2026-32634</title>
    <updated>2026-10-06T23:30:36.540359+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised server name and the discovered IP address for dynamic servers, but later builds connection URIs from the untrusted advertised name instead of the discovered IP. When a dynamic server reports itself as protected, Glances also uses that same untrusted name as the lookup key for saved passwords and the global `[passwords] default` credential. An attacker on the same local network can advertise a fake Glances service over Zeroconf and cause the browser to automatically send a reusable Glances authentication secret to an attacker-controlled host. This affects the background polling path and the REST/WebUI click-through path in Central Browser mode. Version 4.5.2 fixes the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32634"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vx5f-957p-qpvm</id>
    <title>GHSA-vx5f-957p-qpvm — Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers</title>
    <updated>2026-10-06T23:30:36.540386+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: Glances</p>
<p>## Summary</p>
<p>In Central Browser mode, Glances stores both the Zeroconf-advertised server name and the discovered IP address for dynamic servers, but later builds connection URIs from the untrusted advertised name instead of the discovered IP. When a dynamic server reports itself as protected, Glances also uses that same untrusted name as the lookup key for saved passwords and the global `[passwords] default` credential.</p>
<p>An attacker on the same local network can advertise a fake Glances service over Zeroconf and cause the browser to automatically send a reusable Glances authentication secret to an attacker-controlled host. This affects the background polling path and the REST/WebUI click-through path in Central Browser mode.</p>
<p>## Details</p>
<p>Dynamic server discovery keeps both a short `name` and a separate `ip`:</p>
<p>```python
# glances/servers_list_dynamic.py:56-61
def add_server(self, name, ip, port, protocol='rpc'):
    new_server = {
        'key': name,
        'name': name.split(':')[0],  # Short name
        'ip': ip,  # IP address seen by the client
        'port': port,
        ...
        'type': 'DYNAMIC',
    }
```</p>
<p>The Zeroconf listener populates those fields directly from the service advertisement:</p>
<p>```python
# glances/servers_list_dynamic.py:112-121
new_server_ip = socket.inet_ntoa(address)
new_server_port = info.port
...
self.servers.add_server(
    srv_name,
    new_server_ip,
    new_server_port,
    protocol=new_server_protocol,
)
```</p>
<p>However, the Central Browser…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vx5f-957p-qpvm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10415-1</id>
    <title>openSUSE-SU-2026:10415-1 — glances-common-4.5.2-1.1 on GA media</title>
    <updated>2026-10-06T23:30:36.540465+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>glances-common-4.5.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10415-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2172</id>
    <title>PYSEC-2026-2172</title>
    <updated>2026-10-06T23:30:36.540488+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: glances</p>
<p>Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised server name and the discovered IP address for dynamic servers, but later builds connection URIs from the untrusted advertised name instead of the discovered IP. When a dynamic server reports itself as protected, Glances also uses that same untrusted name as the lookup key for saved passwords and the global `[passwords] default` credential. An attacker on the same local network can advertise a fake Glances service over Zeroconf and cause the browser to automatically send a reusable Glances authentication secret to an attacker-controlled host. This affects the background polling path and the REST/WebUI click-through path in Central Browser mode. Version 4.5.2 fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2172"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-32634</id>
    <title>UBUNTU-CVE-2026-32634</title>
    <updated>2026-10-06T23:30:36.540520+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: glances, Ubuntu:Pro:18.04:LTS: glances, Ubuntu:Pro:20.04:LTS: glances, Ubuntu:22.04:LTS: glances, Ubuntu:24.04:LTS: glances, Ubuntu:25.10: glances, Ubuntu:26.04:LTS: glances</p>
<p>Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised server name and the discovered IP address for dynamic servers, but later builds connection URIs from the untrusted advertised name instead of the discovered IP. When a dynamic server reports itself as protected, Glances also uses that same untrusted name as the lookup key for saved passwords and the global `[passwords] default` credential. An attacker on the same local network can advertise a fake Glances service over Zeroconf and cause the browser to automatically send a reusable Glances authentication secret to an attacker-controlled host. This affects the background polling path and the REST/WebUI click-through path in Central Browser mode. Version 4.5.2 fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-32634"/>
  </entry>
</feed>
