πŸ” CVE Alert

CVE-2026-34839

UNKNOWN 0.0

Glances Vulnerable to Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes a REST API (`/api/4/*`) that is accessible without authentication and allows cross-origin requests from any origin due to a permissive CORS policy (`Access-Control-Allow-Origin: *`). This allows a malicious website to read sensitive system information from a running Glances instance in the victim’s browser, leading to cross-origin data exfiltration. While a previous advisory exists for XML-RPC CORS issues, this report demonstrates that the REST API (`/api/4/*`) is also affected and exposes significantly more sensitive data. Version 4.5.4 patches the issue.

CWE CWE-200 CWE-942 CWE-306
Vendor nicolargo
Product glances
Published Apr 20, 2026
Stay Ahead of the Next One

Get instant alerts for nicolargo glances

Be the first to know when new unknown vulnerabilities affecting nicolargo glances are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

nicolargo / glances
< 4.5.4

References

NVD β†— CVE.org β†— EPSS Data β†—
github.com: https://github.com/nicolargo/glances/security/advisories/GHSA-gfc2-9qmw-w7vh github.com: https://github.com/nicolargo/glances/commit/fdfb977b1d91b5e410bc06c4e19f8bedb0005ce9