THREAT OPS › Threat News › [GHSA] GHSA-fp27-88fp-2phg (medium) — Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
[GHSA] GHSA-fp27-88fp-2phg (medium) — Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
GHSA-fp27-88fp-2phg Severity: medium CVE: CVE-2026-68517
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
### Summary Glances's REST API server includes a documented safety check intended to guarantee that `cors_credentials=True` can never be combined with an unrestricted CORS origin allowlist. T
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-68517cve
- CVE-2026-46608cve
- https://trusted.example.com`url
- http://127.0.0.1:36212/api/4/cpuurl
- https://totally-evil-attacker.comurl
- http://127.0.0.1:36212/api/4/processlisturl
Original source: https://github.com/advisories/GHSA-fp27-88fp-2phg