<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:52:25.909035+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-glances-cve-2026-68517</id>
    <title>BREW-glances-CVE-2026-68517 — Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin All…</title>
    <updated>2026-10-03T21:52:25.911522+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: glances</p>
<p>Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list containing the wildcard to retain cors_credentials and expose authenticated REST API data to an untrusted website visited by a previously authenticated user. This issue is fixed in 4.5.6.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-glances-cve-2026-68517"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-68517</id>
    <title>CVE-2026-68517 — Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin All…</title>
    <updated>2026-10-03T21:52:25.911578+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> nicolargo glances</p>
<p>Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list containing the wildcard to retain cors_credentials and expose authenticated REST API data to an untrusted website visited by a previously authenticated user. This issue is fixed in 4.5.6.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-68517"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fp27-88fp-2phg</id>
    <title>GHSA-fp27-88fp-2phg — Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin All…</title>
    <updated>2026-10-03T21:52:25.911610+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: glances</p>
<p>### Summary
Glances's REST API server includes a documented safety check intended to guarantee that `cors_credentials=True` can never be combined with an unrestricted CORS origin allowlist. The check compares the configured origin list to the wildcard using exact list equality (`cors_origins == ["*"]`) instead of a membership test. Any multi-entry origin configuration that merely includes `"*"` alongside other origins (e.g. `cors_origins=*,https://trusted.example.com`) bypasses the check entirely, while Starlette's underlying `CORSMiddleware` still treats the presence of `"*"` anywhere in the list as "allow all origins" and reflects the request's actual `Origin` header together with `Access-Control-Allow-Credentials: true`. This allows any website to read a victim's authenticated Glances monitoring data — including full process lists with command-line arguments — by exploiting the browser's automatic replay of cached HTTP Basic Auth credentials in a cross-origin request.</p>
<p>### Details
`glances/outputs/glances_restful_api.py:298`:
```python
if cors_origins == ["*"] and cors_credentials:
    logger.warning(...)
    cors_credentials = False
```
The intended guarantee is documented in `glances/outputs/glances_stdout_api_restful_doc.py:247-260`: *"Setting cors_credentials=True with cors_origins=* is not allowed. Glances will automatically disable credentials and log a warning if this combination is detected."* The exact-equality comparison only matches when `cors_origins` is preci…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fp27-88fp-2phg"/>
  </entry>
</feed>
