Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4h34-v6r8-mmjc | Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config |
Mon, 17 Aug 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nicolargo
Nicolargo glances |
|
| Vendors & Products |
Nicolargo
Nicolargo glances |
Mon, 17 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py checks only option names and exposes public_username and credentials embedded in public_api values through unauthenticated GET /api/4/config and GET /api/4/config/ip requests. This issue is fixed in 4.5.6. | |
| Title | Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-17T17:06:06.446Z
Reserved: 2026-07-30T16:19:08.082Z
Link: CVE-2026-68520
No data.
Status : Received
Published: 2026-08-17T18:18:06.753
Modified: 2026-08-17T18:18:06.753
Link: CVE-2026-68520
No data.
OpenCVE Enrichment
Updated: 2026-08-17T18:30:04Z
Github GHSA