id: PYSEC-2026-2169 published: "2026-03-18T17:16:06.947Z" modified: "2026-07-13T05:48:56.083829Z" aliases: - CVE-2026-32610 - GHSA-9jfm-9rc6-2hfq details: Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server ships with a default CORS configuration that sets `allow_origins=["*"]` combined with `allow_credentials=True`. When both of these options are enabled together, Starlette's `CORSMiddleware` reflects the requesting `Origin` header value in the `Access-Control-Allow-Origin` response header instead of returning the literal `*` wildcard. This effectively grants any website the ability to make credentialed cross-origin API requests to the Glances server, enabling cross-site data theft of system monitoring information, configuration secrets, and command line arguments from any user who has an active browser session with a Glances instance. Version 4.5.2 fixes the issue. affected: - package: name: glances ecosystem: PyPI purl: pkg:pypi/glances ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 4.5.2 versions: - 1.3.1 - 1.3.2 - 1.3.3 - 1.3.4 - 1.3.5 - 1.3.6 - 1.3.7 - "1.4" - 1.4.1 - 1.4.1.1 - 1.4.2 - 1.4.2.1 - "1.5" - 1.5.1 - 1.5.2 - "1.6" - 1.6.1 - "1.7" - 1.7.1 - 1.7.2 - 1.7.3 - 1.7.4 - 1.7.5 - 1.7.6 - 1.7.7 - "2.0" - 2.0.1 - "2.1" - 2.1.1 - 2.1.2 - "2.10" - "2.11" - 2.11.1 - "2.2" - 2.2.1 - "2.3" - "2.4" - 2.4.1 - 2.4.2 - "2.5" - 2.5.1 - "2.6" - 2.6.1 - 2.6.2 - "2.7" - 2.7.1 - "2.8" - 2.8.1 - 2.8.2 - 2.8.3 - 2.8.4 - 2.8.5 - 2.8.6 - 2.8.7 - 2.8.8 - 2.9.0 - 2.9.1 - "3.0" - 3.0.1 - 3.0.2 - 3.1.0 - 3.1.1 - 3.1.2 - 3.1.3 - 3.1.4 - 3.1.4.1 - 3.1.5 - 3.1.6 - 3.1.6.1 - 3.1.6.2 - 3.1.7 - 3.2.0 - 3.2.1 - 3.2.2 - 3.2.3 - 3.2.3.1 - 3.2.4 - 3.2.4.1 - 3.2.4.2 - 3.2.5 - 3.2.6.1 - 3.2.6.2 - 3.2.6.3 - 3.2.6.4 - 3.2.7 - 3.3.0 - 3.3.0.1 - 3.3.0.2 - 3.3.0.3 - 3.3.0.4 - 3.3.1 - 3.3.1.1 - 3.4.0 - 3.4.0.1 - 3.4.0.2 - 3.4.0.3 - 3.4.0.4 - 3.4.0.5 - 4.0.1 - 4.0.2 - 4.0.3 - 4.0.4 - 4.0.5 - 4.0.6 - 4.0.7 - 4.0.8 - 4.1.0 - 4.1.1 - 4.1.2 - 4.2.0 - 4.2.1 - 4.3.0 - 4.3.0.1 - 4.3.0.3 - 4.3.0.4 - 4.3.0.5 - 4.3.0.6 - 4.3.0.7 - 4.3.0.8 - 4.3.1 - 4.3.2 - 4.3.3 - 4.4.0 - 4.4.1 - 4.5.0 - 4.5.0.1 - 4.5.0.2 - 4.5.0.3 - 4.5.0.4 - 4.5.0.5 - 4.5.1 ecosystem_specific: {} references: - type: ADVISORY url: https://github.com/nicolargo/glances/releases/tag/v4.5.2 - type: FIX url: https://github.com/nicolargo/glances/commit/4465169b71d93991f1e49740fe02428291099832 - type: EVIDENCE url: https://github.com/nicolargo/glances/security/advisories/GHSA-9jfm-9rc6-2hfq severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N