PT-2026-49095 · Glance+1 · Glance+1

·

CVE-2026-46611

·

Published

2026-06-13

·

Updated

2026-08-13

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Glances versions prior to 4.5.5
Description The XML-RPC server (implemented in glances/server.py and started with glances -s) fails to validate the HTTP Host header. This allows a DNS rebinding attack, where an attacker can bypass the same-origin policy to exfiltrate the complete system monitoring dataset through a victim's browser. DNS rebinding is a technique used to trick a browser into making requests to a local or private network resource by manipulating DNS records.
Recommendations Update to version 4.5.5.

Exploit

Fix

DoS

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46611
GHSA-W856-8P3R-P338
OPENSUSE-SU-2026:11122-1
PYSEC-2026-2498

Affected Products

Glance
Red Os