CVE-2026-35587 Details
Description
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, a Server-Side Request Forgery (SSRF) vulnerability exists in the Glances IP plugin due to improper validation of the public_api configuration parameter. The value of public_api is used directly in outbound HTTP requests without any scheme restriction or hostname/IP validation. An attacker who can modify the Glances configuration can force the application to send requests to arbitrary internal or external endpoints. Additionally, when public_username and public_password are set, Glances automatically includes these credentials in the Authorization: Basic header, resulting in credential leakage to attacker-controlled servers. This vulnerability can be exploited to access internal network services, retrieve sensitive data from cloud metadata endpoints, and/or exfiltrate credentials via outbound HTTP requests. The issue arises because public_api is passed directly to the HTTP client (urlopen_auth) without validation, allowing unrestricted outbound connections and unintended disclosure of sensitive information. Version 4.5.4 contains a patch.
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Glances IP plugin, prior to version 4.5.4. The issue arises from inadequate validation of the public_api configuration parameter, which is used in outbound HTTP requests without proper scheme or hostname/IP validation. This vulnerability allows an attacker to manipulate the application into sending requests to arbitrary internal or external endpoints. Furthermore, if public_username and public_password are configured, these credentials are automatically included in the Authorization: Basic header, leading to unauthorized disclosure of sensitive information to attacker-controlled servers. Exploitation of this vulnerability could facilitate access to internal network services, retrieval of sensitive data from cloud metadata endpoints, and exfiltration of credentials via outbound HTTP requests.
Users should update Glances to version 4.5.4 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nicolargo/glances/security/advisories/GHSA-g5pq-48mj-jvw8 | CISA-ADP | ExploitMitigationVendor Advisory |
| https://github.com/nicolargo/glances/commit/d6808be66728956477cc4b544bab1acd71ac65fb | [email protected] | Patch |
| https://github.com/nicolargo/glances/security/advisories/GHSA-g5pq-48mj-jvw8 | [email protected] | ExploitMitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nicolargo glances | < 4.5.4 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | Initial Analysis | [email protected] |
| Apr 22, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | New CVE Received | [email protected] |