<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:38:00 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-15321</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15321</link>
      <description>bdu:2026-15321</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15321</guid>
    </item>
    <item>
      <title>BREW-glances-CVE-2026-46607 — Glances: Insecure Pickle Deserialization in Version Cache Leads to Arbitrary Code Execution</title>
      <link>https://cve.radiocsirt.org/vuln/brew-glances-cve-2026-46607</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache file stored at a predictable, world-accessible path (~/.cache/glances/glances-version.db or $XDG_CACHE_HOME/glances/glances-version.db). No integrity check, signature verification, or format validation is performed before deserialization. An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default). This vulnerability is fixed in 4.5.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache file stored at a predictable, world-accessible path (~/.cache/glances/glances-version.db or $XDG_CACHE_HOME/glances/glances-version.db). No integrity check, signature verification, or format validation is performed before deserialization. An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default). This vulnerability is fixed in 4.5.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-glances-cve-2026-46607</guid>
    </item>
    <item>
      <title>EUVD-2026-330382</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330382</link>
      <description>EUVD-2026-330382</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330382</guid>
    </item>
    <item>
      <title>fkie_cve-2026-46607</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46607</link>
      <description>&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache file stored at a predictable, world-accessible path (~/.cache/glances/glances-version.db or $XDG_CACHE_HOME/glances/glances-version.db). No integrity check, signature verification, or format validation is performed before deserialization. An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default). This vulnerability is fixed in 4.5.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache file stored at a predictable, world-accessible path (~/.cache/glances/glances-version.db or $XDG_CACHE_HOME/glances/glances-version.db). No integrity check, signature verification, or format validation is performed before deserialization. An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default). This vulnerability is fixed in 4.5.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-46607</guid>
    </item>
    <item>
      <title>GHSA-9837-48hr-q32j — Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code Execution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9837-48hr-q32j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: glances&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`glances/outdated.py` uses `pickle.load()` to read a version-check cache file stored at a predictable, world-accessible path (`~/.cache/glances/glances-version.db` or `$XDG_CACHE_HOME/glances/glances-version.db`). No integrity check, signature verification, or format validation is performed before deserialization.  An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default).&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Affected file:** `glances/outdated.py`, method `Outdated._load_cache()`, line 121&lt;/p&gt;
&lt;p&gt;**Direct URL (commit 04579778e733d705898a169e049dc84772c852da):**
- https://github.com/nicolargo/glances/blob/04579778e733d705898a169e049dc84772c852da/glances/outdated.py#L121&lt;/p&gt;
&lt;p&gt;```python
# outdated.py  (_load_cache, line 119-127)
try:
    with open(self.cache_file, &amp;#39;rb&amp;#39;) as f:
        cached_data = pickle.load(f)          # ← no integrity check
except Exception as e:
    logger.debug(f&amp;#34;Cannot read version from cache file: {self.cache_file} ({e})&amp;#34;)
    ...
```&lt;/p&gt;
&lt;p&gt;`self.cache_file` is constructed from the XDG cache directory path at `Outdated.__init__()`:&lt;/p&gt;
&lt;p&gt;```python
# outdated.py  (__init__)
self.cache_file = os.path.join(
    user_cache_dir(&amp;#39;glances&amp;#39;)[0],
    &amp;#39;glances-version.db&amp;#39;
)
```&lt;/p&gt;
&lt;p&gt;On a default Linux installation this resolves to `/home/john/.cache/glances/glances-ve…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: glances&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`glances/outdated.py` uses `pickle.load()` to read a version-check cache file stored at a predictable, world-accessible path (`~/.cache/glances/glances-version.db` or `$XDG_CACHE_HOME/glances/glances-version.db`). No integrity check, signature verification, or format validation is performed before deserialization.  An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default).&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Affected file:** `glances/outdated.py`, method `Outdated._load_cache()`, line 121&lt;/p&gt;
&lt;p&gt;**Direct URL (commit 04579778e733d705898a169e049dc84772c852da):**
- https://github.com/nicolargo/glances/blob/04579778e733d705898a169e049dc84772c852da/glances/outdated.py#L121&lt;/p&gt;
&lt;p&gt;```python
# outdated.py  (_load_cache, line 119-127)
try:
    with open(self.cache_file, &amp;#39;rb&amp;#39;) as f:
        cached_data = pickle.load(f)          # ← no integrity check
except Exception as e:
    logger.debug(f&amp;#34;Cannot read version from cache file: {self.cache_file} ({e})&amp;#34;)
    ...
```&lt;/p&gt;
&lt;p&gt;`self.cache_file` is constructed from the XDG cache directory path at `Outdated.__init__()`:&lt;/p&gt;
&lt;p&gt;```python
# outdated.py  (__init__)
self.cache_file = os.path.join(
    user_cache_dir(&amp;#39;glances&amp;#39;)[0],
    &amp;#39;glances-version.db&amp;#39;
)
```&lt;/p&gt;
&lt;p&gt;On a default Linux installation this resolves to `/home/john/.cache/glances/glances-ve…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9837-48hr-q32j</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11122-1 — glances-common-4.5.5-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11122-1</link>
      <description>&lt;p&gt;glances-common-4.5.5-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;glances-common-4.5.5-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11122-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-2496 — Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code Execution</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2496</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: glances&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`glances/outdated.py` uses `pickle.load()` to read a version-check cache file stored at a predictable, world-accessible path (`~/.cache/glances/glances-version.db` or `$XDG_CACHE_HOME/glances/glances-version.db`). No integrity check, signature verification, or format validation is performed before deserialization.  An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default).&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Affected file:** `glances/outdated.py`, method `Outdated._load_cache()`, line 121&lt;/p&gt;
&lt;p&gt;**Direct URL (commit 04579778e733d705898a169e049dc84772c852da):**
- https://github.com/nicolargo/glances/blob/04579778e733d705898a169e049dc84772c852da/glances/outdated.py#L121&lt;/p&gt;
&lt;p&gt;```python
# outdated.py  (_load_cache, line 119-127)
try:
    with open(self.cache_file, &amp;#39;rb&amp;#39;) as f:
        cached_data = pickle.load(f)          # ← no integrity check
except Exception as e:
    logger.debug(f&amp;#34;Cannot read version from cache file: {self.cache_file} ({e})&amp;#34;)
    ...
```&lt;/p&gt;
&lt;p&gt;`self.cache_file` is constructed from the XDG cache directory path at `Outdated.__init__()`:&lt;/p&gt;
&lt;p&gt;```python
# outdated.py  (__init__)
self.cache_file = os.path.join(
    user_cache_dir(&amp;#39;glances&amp;#39;)[0],
    &amp;#39;glances-version.db&amp;#39;
)
```&lt;/p&gt;
&lt;p&gt;On a default Linux installation this resolves to `/home/john/.cache/glances/glances-ve…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: glances&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`glances/outdated.py` uses `pickle.load()` to read a version-check cache file stored at a predictable, world-accessible path (`~/.cache/glances/glances-version.db` or `$XDG_CACHE_HOME/glances/glances-version.db`). No integrity check, signature verification, or format validation is performed before deserialization.  An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default).&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Affected file:** `glances/outdated.py`, method `Outdated._load_cache()`, line 121&lt;/p&gt;
&lt;p&gt;**Direct URL (commit 04579778e733d705898a169e049dc84772c852da):**
- https://github.com/nicolargo/glances/blob/04579778e733d705898a169e049dc84772c852da/glances/outdated.py#L121&lt;/p&gt;
&lt;p&gt;```python
# outdated.py  (_load_cache, line 119-127)
try:
    with open(self.cache_file, &amp;#39;rb&amp;#39;) as f:
        cached_data = pickle.load(f)          # ← no integrity check
except Exception as e:
    logger.debug(f&amp;#34;Cannot read version from cache file: {self.cache_file} ({e})&amp;#34;)
    ...
```&lt;/p&gt;
&lt;p&gt;`self.cache_file` is constructed from the XDG cache directory path at `Outdated.__init__()`:&lt;/p&gt;
&lt;p&gt;```python
# outdated.py  (__init__)
self.cache_file = os.path.join(
    user_cache_dir(&amp;#39;glances&amp;#39;)[0],
    &amp;#39;glances-version.db&amp;#39;
)
```&lt;/p&gt;
&lt;p&gt;On a default Linux installation this resolves to `/home/john/.cache/glances/glances-ve…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2496</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-46607</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46607</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: glances, Ubuntu:Pro:18.04:LTS: glances, Ubuntu:Pro:20.04:LTS: glances, Ubuntu:22.04:LTS: glances, Ubuntu:24.04:LTS: glances, Ubuntu:25.10: glances, Ubuntu:26.04:LTS: glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache file stored at a predictable, world-accessible path (~/.cache/glances/glances-version.db or $XDG_CACHE_HOME/glances/glances-version.db). No integrity check, signature verification, or format validation is performed before deserialization. An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default). This vulnerability is fixed in 4.5.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: glances, Ubuntu:Pro:18.04:LTS: glances, Ubuntu:Pro:20.04:LTS: glances, Ubuntu:22.04:LTS: glances, Ubuntu:24.04:LTS: glances, Ubuntu:25.10: glances, Ubuntu:26.04:LTS: glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache file stored at a predictable, world-accessible path (~/.cache/glances/glances-version.db or $XDG_CACHE_HOME/glances/glances-version.db). No integrity check, signature verification, or format validation is performed before deserialization. An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default). This vulnerability is fixed in 4.5.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46607</guid>
    </item>
  </channel>
</rss>
