This release includes 3 security fixes for security teams reviewing exposed deployments.
Topics
+2 more
Summary
AI summaryAddresses three critical security vulnerabilities in IP plugin, REST API, and Cassandra support.
Full changelog
Bug corrected:
- Cannot set warning/critical temperature for a specific sensor #3525
- Memory percentage and used displayed as negative numbers #3358
- Incorrect Docker container count via Homeassistant Integration #3433
- Fix LXD filter excluding containers on standalone hosts #3529
Enhancements:
- Add Rockchip MPP plugin for hardware encoder/decoder monitoring #3514
- Clamp memory used/percent to non-negative values for LXC containers #3505
- Support single-core Rockchip NPU load parsing and improve device naming #3499
Security patches:
- SSRF in Glances IP Plugin via public_api leads to credential leakage - Correct CVE-2026-35587
- Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) - Correct CVE-2026-34839
- fix(cassandra): validate keyspace/table/replication_factor to prevent CQL injection - Correct CVE-2026-35588 #3520
Continious integration and documentation:
- pycache file is put in wheel #3516
- Remove dead code #3507
Thanks to all the contributors for this version: csvke, Christian Rishøj,
duriantaco, Julio César Suástegui, Paul and morimori-dev.
Security Fixes
- SSRF in IP Plugin via public_api leading to credential leakage (CVE-2026-35587)
- Cross-Origin Information Disclosure via unauthenticated REST API /api/4 (CVE-2026-34839)
- CQL injection prevention in Cassandra plugin (CVE-2026-35588)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About glances
Glances an Eye on your system. A top/htop alternative for GNU/Linux, BSD, Mac OS and Windows operating systems.
Related context
Related tools
Beta — feedback welcome: [email protected]