Executive brief
Glances is a system monitoring tool used to track performance metrics like CPU, memory, and running processes. A security flaw in its server component allows an attacker to trick a user's web browser into bypassing security boundaries. If a user visits a malicious website while Glances is running, the attacker can steal sensitive system information, including full process lists which often contain passwords or API keys.
Technical details
The Glances XML-RPC server (implemented in glances/server.py) inherits from Python's SimpleXMLRPCRequestHandler but fails to implement Host header validation. This omission, combined with an unrestricted 'Access-Control-Allow-Origin: *' header, enables DNS rebinding attacks. An attacker can lure a victim to a malicious website that, after a DNS TTL expiry, rebinds to the local or network IP where Glances is running. Because the server does not verify the Host header, the victim's browser will treat the attacker's site as same-origin and forward the request, allowing the attacker to exfiltrate the full system monitoring dataset (including process command lines, OS details, and network stats). This vulnerability is fixed in version 4.5.5.
Affected products
- nicolargo Glances < 4.5.5
Timeline
- 2026-06-13: patched: Version 4.5.5 released
- 2026-06-25: disclosed: CVE-2026-46611 published