THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fp27-88fp-2phg (medium) — Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard

[GHSA] GHSA-fp27-88fp-2phg (medium) — Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard

highgithub_advisoriesPublished 2026-08-17

GHSA-fp27-88fp-2phg Severity: medium CVE: CVE-2026-68517

Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard

### Summary Glances's REST API server includes a documented safety check intended to guarantee that `cors_credentials=True` can never be combined with an unrestricted CORS origin allowlist. T

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-fp27-88fp-2phg