PT-2026-61693 · Glance · Glance

·

CVE-2026-63770

·

Published

2026-07-20

·

Updated

2026-08-21

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Glance version 0.8.5
Description An IP address spoofing issue exists in the authentication handler when the server proxied option is enabled. Unauthenticated attackers can bypass brute-force lockout protections by providing arbitrary values in the X-Forwarded-For request header. By manipulating the leftmost value of this header, attackers can make each login attempt appear to come from a different IP address, preventing the per-IP failed-login counter from triggering a lockout and allowing unlimited credential guessing against the authentication endpoint.
Recommendations For version 0.8.5, disable the server proxied option as a temporary mitigation to prevent the bypass of brute-force protections.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63770

Affected Products

Glance