<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:16:23 +0000</lastBuildDate>
    <item>
      <title>BREW-glances-CVE-2026-68517 — Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin All…</title>
      <link>https://cve.radiocsirt.org/vuln/brew-glances-cve-2026-68517</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list containing the wildcard to retain cors_credentials and expose authenticated REST API data to an untrusted website visited by a previously authenticated user. This issue is fixed in 4.5.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list containing the wildcard to retain cors_credentials and expose authenticated REST API data to an untrusted website visited by a previously authenticated user. This issue is fixed in 4.5.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-glances-cve-2026-68517</guid>
    </item>
    <item>
      <title>EUVD-2026-354995</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-354995</link>
      <description>EUVD-2026-354995</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-354995</guid>
    </item>
    <item>
      <title>fkie_cve-2026-68517</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68517</link>
      <description>&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list containing the wildcard to retain cors_credentials and expose authenticated REST API data to an untrusted website visited by a previously authenticated user. This issue is fixed in 4.5.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list containing the wildcard to retain cors_credentials and expose authenticated REST API data to an untrusted website visited by a previously authenticated user. This issue is fixed in 4.5.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-68517</guid>
    </item>
    <item>
      <title>GHSA-fp27-88fp-2phg — Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin All…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fp27-88fp-2phg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: glances&lt;/p&gt;
&lt;p&gt;### Summary
Glances&amp;#39;s REST API server includes a documented safety check intended to guarantee that `cors_credentials=True` can never be combined with an unrestricted CORS origin allowlist. The check compares the configured origin list to the wildcard using exact list equality (`cors_origins == [&amp;#34;*&amp;#34;]`) instead of a membership test. Any multi-entry origin configuration that merely includes `&amp;#34;*&amp;#34;` alongside other origins (e.g. `cors_origins=*,https://trusted.example.com`) bypasses the check entirely, while Starlette&amp;#39;s underlying `CORSMiddleware` still treats the presence of `&amp;#34;*&amp;#34;` anywhere in the list as &amp;#34;allow all origins&amp;#34; and reflects the request&amp;#39;s actual `Origin` header together with `Access-Control-Allow-Credentials: true`. This allows any website to read a victim&amp;#39;s authenticated Glances monitoring data — including full process lists with command-line arguments — by exploiting the browser&amp;#39;s automatic replay of cached HTTP Basic Auth credentials in a cross-origin request.&lt;/p&gt;
&lt;p&gt;### Details
`glances/outputs/glances_restful_api.py:298`:
```python
if cors_origins == [&amp;#34;*&amp;#34;] and cors_credentials:
    logger.warning(...)
    cors_credentials = False
```
The intended guarantee is documented in `glances/outputs/glances_stdout_api_restful_doc.py:247-260`: *&amp;#34;Setting cors_credentials=True with cors_origins=* is not allowed. Glances will automatically disable credentials and log a warning if this combination is detected.&amp;#34;* The exact-equality comparison only matches when `cors_origins` is preci…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: glances&lt;/p&gt;
&lt;p&gt;### Summary
Glances&amp;#39;s REST API server includes a documented safety check intended to guarantee that `cors_credentials=True` can never be combined with an unrestricted CORS origin allowlist. The check compares the configured origin list to the wildcard using exact list equality (`cors_origins == [&amp;#34;*&amp;#34;]`) instead of a membership test. Any multi-entry origin configuration that merely includes `&amp;#34;*&amp;#34;` alongside other origins (e.g. `cors_origins=*,https://trusted.example.com`) bypasses the check entirely, while Starlette&amp;#39;s underlying `CORSMiddleware` still treats the presence of `&amp;#34;*&amp;#34;` anywhere in the list as &amp;#34;allow all origins&amp;#34; and reflects the request&amp;#39;s actual `Origin` header together with `Access-Control-Allow-Credentials: true`. This allows any website to read a victim&amp;#39;s authenticated Glances monitoring data — including full process lists with command-line arguments — by exploiting the browser&amp;#39;s automatic replay of cached HTTP Basic Auth credentials in a cross-origin request.&lt;/p&gt;
&lt;p&gt;### Details
`glances/outputs/glances_restful_api.py:298`:
```python
if cors_origins == [&amp;#34;*&amp;#34;] and cors_credentials:
    logger.warning(...)
    cors_credentials = False
```
The intended guarantee is documented in `glances/outputs/glances_stdout_api_restful_doc.py:247-260`: *&amp;#34;Setting cors_credentials=True with cors_origins=* is not allowed. Glances will automatically disable credentials and log a warning if this combination is detected.&amp;#34;* The exact-equality comparison only matches when `cors_origins` is preci…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fp27-88fp-2phg</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11674-1 — glances-common-4.5.6-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11674-1</link>
      <description>&lt;p&gt;glances-common-4.5.6-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;glances-common-4.5.6-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11674-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-3667 — Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin All…</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3667</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: glances&lt;/p&gt;
&lt;p&gt;### Summary
Glances&amp;#39;s REST API server includes a documented safety check intended to guarantee that `cors_credentials=True` can never be combined with an unrestricted CORS origin allowlist. The check compares the configured origin list to the wildcard using exact list equality (`cors_origins == [&amp;#34;*&amp;#34;]`) instead of a membership test. Any multi-entry origin configuration that merely includes `&amp;#34;*&amp;#34;` alongside other origins (e.g. `cors_origins=*,https://trusted.example.com`) bypasses the check entirely, while Starlette&amp;#39;s underlying `CORSMiddleware` still treats the presence of `&amp;#34;*&amp;#34;` anywhere in the list as &amp;#34;allow all origins&amp;#34; and reflects the request&amp;#39;s actual `Origin` header together with `Access-Control-Allow-Credentials: true`. This allows any website to read a victim&amp;#39;s authenticated Glances monitoring data — including full process lists with command-line arguments — by exploiting the browser&amp;#39;s automatic replay of cached HTTP Basic Auth credentials in a cross-origin request.&lt;/p&gt;
&lt;p&gt;### Details
`glances/outputs/glances_restful_api.py:298`:
```python
if cors_origins == [&amp;#34;*&amp;#34;] and cors_credentials:
    logger.warning(...)
    cors_credentials = False
```
The intended guarantee is documented in `glances/outputs/glances_stdout_api_restful_doc.py:247-260`: *&amp;#34;Setting cors_credentials=True with cors_origins=* is not allowed. Glances will automatically disable credentials and log a warning if this combination is detected.&amp;#34;* The exact-equality comparison only matches when `cors_origins` is preci…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: glances&lt;/p&gt;
&lt;p&gt;### Summary
Glances&amp;#39;s REST API server includes a documented safety check intended to guarantee that `cors_credentials=True` can never be combined with an unrestricted CORS origin allowlist. The check compares the configured origin list to the wildcard using exact list equality (`cors_origins == [&amp;#34;*&amp;#34;]`) instead of a membership test. Any multi-entry origin configuration that merely includes `&amp;#34;*&amp;#34;` alongside other origins (e.g. `cors_origins=*,https://trusted.example.com`) bypasses the check entirely, while Starlette&amp;#39;s underlying `CORSMiddleware` still treats the presence of `&amp;#34;*&amp;#34;` anywhere in the list as &amp;#34;allow all origins&amp;#34; and reflects the request&amp;#39;s actual `Origin` header together with `Access-Control-Allow-Credentials: true`. This allows any website to read a victim&amp;#39;s authenticated Glances monitoring data — including full process lists with command-line arguments — by exploiting the browser&amp;#39;s automatic replay of cached HTTP Basic Auth credentials in a cross-origin request.&lt;/p&gt;
&lt;p&gt;### Details
`glances/outputs/glances_restful_api.py:298`:
```python
if cors_origins == [&amp;#34;*&amp;#34;] and cors_credentials:
    logger.warning(...)
    cors_credentials = False
```
The intended guarantee is documented in `glances/outputs/glances_stdout_api_restful_doc.py:247-260`: *&amp;#34;Setting cors_credentials=True with cors_origins=* is not allowed. Glances will automatically disable credentials and log a warning if this combination is detected.&amp;#34;* The exact-equality comparison only matches when `cors_origins` is preci…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3667</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-68517</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68517</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: glances, Ubuntu:Pro:18.04:LTS: glances, Ubuntu:Pro:20.04:LTS: glances, Ubuntu:22.04:LTS: glances, Ubuntu:24.04:LTS: glances, Ubuntu:26.04:LTS: glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list containing the wildcard to retain cors_credentials and expose authenticated REST API data to an untrusted website visited by a previously authenticated user. This issue is fixed in 4.5.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: glances, Ubuntu:Pro:18.04:LTS: glances, Ubuntu:Pro:20.04:LTS: glances, Ubuntu:22.04:LTS: glances, Ubuntu:24.04:LTS: glances, Ubuntu:26.04:LTS: glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list containing the wildcard to retain cors_credentials and expose authenticated REST API data to an untrusted website visited by a previously authenticated user. This issue is fixed in 4.5.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68517</guid>
    </item>
  </channel>
</rss>
