<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 17:57:52 +0000</lastBuildDate>
    <item>
      <title>BREW-glances-CVE-2026-68520 — Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config</title>
      <link>https://cve.radiocsirt.org/vuln/brew-glances-cve-2026-68520</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py checks only option names and exposes public_username and credentials embedded in public_api values through unauthenticated GET /api/4/config and GET /api/4/config/ip requests. This issue is fixed in 4.5.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py checks only option names and exposes public_username and credentials embedded in public_api values through unauthenticated GET /api/4/config and GET /api/4/config/ip requests. This issue is fixed in 4.5.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-glances-cve-2026-68520</guid>
    </item>
    <item>
      <title>CVE-2026-68520 — Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-68520</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; nicolargo glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py checks only option names and exposes public_username and credentials embedded in public_api values through unauthenticated GET /api/4/config and GET /api/4/config/ip requests. This issue is fixed in 4.5.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; nicolargo glances&lt;/p&gt;
&lt;p&gt;Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py checks only option names and exposes public_username and credentials embedded in public_api values through unauthenticated GET /api/4/config and GET /api/4/config/ip requests. This issue is fixed in 4.5.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-68520</guid>
    </item>
    <item>
      <title>GHSA-4h34-v6r8-mmjc — Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4h34-v6r8-mmjc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: glances&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Glances provides `as_dict_secure()` explicitly designed for unauthenticated API access, with a docstring stating it returns &amp;#34;a sanitised copy of the configuration dict&amp;#34; where &amp;#34;Sensitive keys in remaining sections are replaced by &amp;#39;********&amp;#39;&amp;#34;. However, the implementation only checks KEY names against a regex pattern and never inspects VALUE content. The documented `[ip]` config section supports `public_api` (URL), `public_username` (login), and `public_password` (password). While `public_password` is correctly masked, both `public_api` (when containing embedded credentials like `https://user:pass@host/`) and `public_username` are returned in full to unauthenticated users via `GET /api/4/config`.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;Glances latest (Docker: `nicolargo/glances:latest`)&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;In `glances/config.py`, `as_dict_secure()`:
```python
_SECURE_SENSITIVE_KEY_RE = re.compile(r&amp;#34;password|token|secret|api_key|apikey|ssl_keyfile&amp;#34;, re.IGNORECASE)&lt;/p&gt;
&lt;p&gt;def as_dict_secure(self):
    &amp;#34;&amp;#34;&amp;#34;Return a sanitised copy of the configuration dict.
    Intended for unauthenticated API access.
    - Sensitive keys in remaining sections are replaced by &amp;#39;********&amp;#39;.
    &amp;#34;&amp;#34;&amp;#34;
    sanitized = {}
    for section, options in self.as_dict().items():
        if section in _SECURE_BLOCKED_SECTIONS: continue
        sanitized[section] = {
            key: &amp;#34;********&amp;#34; if _SECURE_SENSITIVE_KEY_RE.search(key) else value
            for key, value in options.items()
        }
    return sanitized
```&lt;/p&gt;
&lt;p&gt;In `…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: glances&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Glances provides `as_dict_secure()` explicitly designed for unauthenticated API access, with a docstring stating it returns &amp;#34;a sanitised copy of the configuration dict&amp;#34; where &amp;#34;Sensitive keys in remaining sections are replaced by &amp;#39;********&amp;#39;&amp;#34;. However, the implementation only checks KEY names against a regex pattern and never inspects VALUE content. The documented `[ip]` config section supports `public_api` (URL), `public_username` (login), and `public_password` (password). While `public_password` is correctly masked, both `public_api` (when containing embedded credentials like `https://user:pass@host/`) and `public_username` are returned in full to unauthenticated users via `GET /api/4/config`.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;Glances latest (Docker: `nicolargo/glances:latest`)&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;In `glances/config.py`, `as_dict_secure()`:
```python
_SECURE_SENSITIVE_KEY_RE = re.compile(r&amp;#34;password|token|secret|api_key|apikey|ssl_keyfile&amp;#34;, re.IGNORECASE)&lt;/p&gt;
&lt;p&gt;def as_dict_secure(self):
    &amp;#34;&amp;#34;&amp;#34;Return a sanitised copy of the configuration dict.
    Intended for unauthenticated API access.
    - Sensitive keys in remaining sections are replaced by &amp;#39;********&amp;#39;.
    &amp;#34;&amp;#34;&amp;#34;
    sanitized = {}
    for section, options in self.as_dict().items():
        if section in _SECURE_BLOCKED_SECTIONS: continue
        sanitized[section] = {
            key: &amp;#34;********&amp;#34; if _SECURE_SENSITIVE_KEY_RE.search(key) else value
            for key, value in options.items()
        }
    return sanitized
```&lt;/p&gt;
&lt;p&gt;In `…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4h34-v6r8-mmjc</guid>
    </item>
  </channel>
</rss>
