{"id":"CVE-2026-35588","aliases":["GHSA-grp3-h8m8-45p7","PYSEC-2026-2177"],"url":"https://o3.security/vulnerability/CVE-2026-35588","summary":"Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values","details":"Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Cassandra export module (`glances/exports/glances_cassandra/__init__.py`) interpolates `keyspace`, `table`, and `replication_factor` configuration values directly into CQL statements without validation. A user with write access to `glances.conf` can redirect all monitoring data to an attacker-controlled Cassandra keyspace. Version 4.5.4 contains a fix.","published":"2026-04-20T23:20:34.998Z","modified":"2026-08-12T03:51:26.493236290Z","cvss":{"score":6.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L"},"epss":{"score":0.00212,"percentile":0.11659,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"glances","fixedVersion":"4.5.4"}],"fix":{"url":"https://github.com/nicolargo/glances/commit/d339181f03a14bb15506307e9d58f876e23d8160","label":"nicolargo/glances@d339181"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35588.json"},{"type":"ADVISORY","url":"https://github.com/nicolargo/glances/security/advisories/GHSA-grp3-h8m8-45p7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35588"},{"type":"FIX","url":"https://github.com/nicolargo/glances/commit/d339181f03a14bb15506307e9d58f876e23d8160"},{"type":"FIX","url":"https://github.com/nicolargo/glances/commit/e41b665576f9fd5374e3152078726cc59a01e48c"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.493236290Z"}}