Technology · PyPI
glances (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 26 vulnerabilities in glances (PyPI): 0 in the last 7 days and 6 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-68520, was published on 17 August 2026.
- Last 7 days
- 0
- Last 90 days
- 6
- Critical, all time
- 0
- Exploited in the wild
- 0
About glances (PyPI)
A cross-platform system monitoring tool that displays system information through a web-based or terminal interface.
Latest glances (PyPI) vulnerabilities
- CVE-2026-68520: Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py…mediumCVSS 5.3EPSS 0.4%
- CVE-2026-68519: Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, GlancesActions.run() in…highCVSS 4EPSS 0.2%
- CVE-2026-62982: Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in…highCVSS 8.8EPSS 0.2%
- CVE-2026-68518: Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in…highCVSS 4EPSS 0.2%
- CVE-2026-68517: Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in…mediumCVSS 6.5EPSS 0.5%
- CVE-2026-32633: PYSEC-2026-343 - Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`lowCVSS 3.1EPSS 0.6%
- CVE-2026-53925: nicolargo Glances command injection in secure_popen via AMP configurationhighCVSS 7.8EPSS 0.2%
- CVE-2026-46611: nicolargo Glances DNS rebinding in XML-RPC servermediumCVSS 5.3EPSS 0.2%
- CVE-2026-46608: nicolargo Glances CORS wildcard fallback in XML-RPC serverhighCVSS 7.4EPSS 0.4%
- CVE-2026-46607: nicolargo Glances insecure pickle deserialization in version cachehighCVSS 7.8EPSS 0.4%
- CVE-2026-46606: nicolargo Glances command injection in virsh.pyhighCVSS 7.8EPSS 0.2%
- CVE-2026-35588: Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config ValuesmediumCVSS 6.3EPSS 0.2%
- CVE-2026-35587: Glances has SSRF in IP Plugin via public_api leading to credential leakagehighCVSS 8.8EPSS 0.5%
- CVE-2026-34839: PYSEC-2026-2175 - Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web…lowCVSS 3.1EPSS 0.5%
- CVE-2026-33641: Glances Vulnerable to Command Injection via Dynamic Configuration ValueshighCVSS 7.8EPSS 0.8%
- CVE-2026-33533: Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS WildcardhighCVSS 4EPSS 0.5%
- CVE-2026-32634: PYSEC-2026-2172 - Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central…lowCVSS 3.1EPSS 0.2%
- CVE-2026-32632: PYSEC-2026-2171 - Glances is an open-source system cross-platform monitoring tool. Glances recently added DNS rebinding…lowCVSS 3.1EPSS 0.2%
- CVE-2026-32611: PYSEC-2026-2170 - Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0)…lowCVSS 3.1EPSS 0.4%
- CVE-2026-32610: PYSEC-2026-2169 - Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances…lowCVSS 3.1EPSS 0.5%
- CVE-2026-32609: PYSEC-2026-2168 - Glances is an open-source system cross-platform monitoring tool. The GHSA-gh4x fix (commit 5d3de60)…lowCVSS 3.1EPSS 0.6%
- CVE-2026-32608: PYSEC-2026-2167 - Glances is an open-source system cross-platform monitoring tool. The Glances action system allows…lowCVSS 3.1EPSS 0.2%
- CVE-2026-32596: nicolargo Glances missing authentication in REST APIhighCVSS 4EPSS 1.8%
- CVE-2026-30930: PYSEC-2026-2165 - Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export…mediumCVSS 4EPSS 0.4%
- CVE-2026-30928: PYSEC-2026-2164 - Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST…mediumCVSS 4EPSS 1.6%
Most severe glances (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-35587: Glances has SSRF in IP Plugin via public_api leading to credential leakagehighCVSS 8.8EPSS 0.5%
- CVE-2026-62982: Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in…highCVSS 8.8EPSS 0.2%
- CVE-2026-33641: Glances Vulnerable to Command Injection via Dynamic Configuration ValueshighCVSS 7.8EPSS 0.8%
- CVE-2026-46607: nicolargo Glances insecure pickle deserialization in version cachehighCVSS 7.8EPSS 0.4%
- CVE-2026-46606: nicolargo Glances command injection in virsh.pyhighCVSS 7.8EPSS 0.2%
- CVE-2026-53925: nicolargo Glances command injection in secure_popen via AMP configurationhighCVSS 7.8EPSS 0.2%
- CVE-2026-46608: nicolargo Glances CORS wildcard fallback in XML-RPC serverhighCVSS 7.4EPSS 0.4%
- CVE-2026-32596: nicolargo Glances missing authentication in REST APIhighCVSS 4EPSS 1.8%
- CVE-2026-33533: Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS WildcardhighCVSS 4EPSS 0.5%
- CVE-2026-68519: Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, GlancesActions.run() in…highCVSS 4EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 5 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/glances.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "glances (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/glances, 26 September 2026.