Skip to content

glances

Monitoring & Metrics

An open‑source, cross‑platform system monitoring tool that provides real‑time dashboards (CLI/web) and remote/API access to CPU, memory, disk, network and container metrics.

Python Latest v4.5.5 · 1mo ago Security brief →

Features

  • Real‑time monitoring of CPU, memory, disks, networks and processes
  • Supports containers (Docker, LXC) and custom plugins
  • Web UI, command‑line dashboard, XML‑RPC/RESTful API and MCP server for AI queries

Recent releases

View all 6 releases →
Upgrade now
v4.5.5 Security relevant
RCE / SSRF Dependencies

Critical security fixes

v4.5.4 Security relevant
Security fixes
  • SSRF in IP Plugin via public_api leading to credential leakage (CVE-2026-35587)
  • Cross-Origin Information Disclosure via unauthenticated REST API /api/4 (CVE-2026-34839)
  • CQL injection prevention in Cassandra plugin (CVE-2026-35588)
Notable features
  • Rockchip MPP hardware encoder/decoder monitoring plugin
  • Single-core Rockchip NPU load parsing support
  • Fixed LXC memory percentage display issues
Full changelog

Bug corrected:

  • Cannot set warning/critical temperature for a specific sensor #3525
  • Memory percentage and used displayed as negative numbers #3358
  • Incorrect Docker container count via Homeassistant Integration #3433
  • Fix LXD filter excluding containers on standalone hosts #3529

Enhancements:

  • Add Rockchip MPP plugin for hardware encoder/decoder monitoring #3514
  • Clamp memory used/percent to non-negative values for LXC containers #3505
  • Support single-core Rockchip NPU load parsing and improve device naming #3499

Security patches:

  • SSRF in Glances IP Plugin via public_api leads to credential leakage - Correct CVE-2026-35587
  • Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) - Correct CVE-2026-34839
  • fix(cassandra): validate keyspace/table/replication_factor to prevent CQL injection - Correct CVE-2026-35588 #3520

Continious integration and documentation:

  • pycache file is put in wheel #3516
  • Remove dead code #3507

Thanks to all the contributors for this version: csvke, Christian Rishøj,
duriantaco, Julio César Suástegui, Paul and morimori-dev.

v4.5.3 Security relevant
Security fixes
  • CVE-2026-33641: Command Injection via Dynamic Configuration Values
  • CVE-2026-33533: Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard
Notable features
  • LXC/LXD container support
  • ClickHouse export functionality
v4.5.2 Security relevant
Breaking changes
  • Host header validation enforced; requests not matching localhost/127.0.0.1 rejected unless allowed_hosts configured
  • CORS policy restrictive; wildcard removed, must explicitly configure cors_origins
  • Sensitive fields redacted on unauthenticated API responses; must authenticate to access password hashes and SNMP credentials
Security fixes
  • CVE-2026-32610: Default CORS Configuration Allows Cross-Origin Credential Theft
  • CVE-2026-32609: Incomplete Secrets Redaction in /api/v4/args Endpoint
  • CVE-2026-32632: REST/WebUI DNS Rebinding Vulnerability
v4.5.1 Bug fix
Notable features
  • Intel GPU monitoring support
  • Docker container health alerting
  • Per-plugin min/max/mean statistics

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
33,086
Forks
1,764
Languages
Python Vue Makefile

Install & Platforms

Install via
pip
Platforms
linux macos windows

Beta — feedback welcome: [email protected]