Debian Package Tracker
Register | Log in
Subscribe

glances

Curses-based monitoring tool

Choose email to subscribe with

general
  • source: glances (main)
  • version: 4.3.3+dfsg-1
  • maintainer: Daniel Echeverri (DMD)
  • uploaders: Sebastien Badia [DMD]
  • arch: all
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 3.3.1.1+dfsg-1
  • stable: 4.3.1+dfsg-1
  • testing: 4.3.3+dfsg-1
  • unstable: 4.3.3+dfsg-1
versioned links
  • 3.3.1.1+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.3.1+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.3.3+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • glances (6 bugs: 0, 4, 2, 0)
  • glances-doc (1 bugs: 0, 1, 0, 0)
action needed
A new upstream version is available: 4.5.1 high
A new upstream version 4.5.1 is available, you should consider packaging it.
Created: 2025-11-26 Last update: 2026-03-12 20:30
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-30928: Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint returns the entire parsed Glances configuration file (glances.conf) via self.config.as_dict() with no filtering of sensitive values. The configuration file contains credentials for all configured backend services including database passwords, API tokens, JWT signing keys, and SSL key passwords. This vulnerability is fixed in 4.5.1.
Created: 2026-03-11 Last update: 2026-03-12 16:30
2 security issues in sid high

There are 2 open security issues in sid.

2 important issues:
  • CVE-2026-30928: Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint returns the entire parsed Glances configuration file (glances.conf) via self.config.as_dict() with no filtering of sensitive values. The configuration file contains credentials for all configured backend services including database passwords, API tokens, JWT signing keys, and SSL key passwords. This vulnerability is fixed in 4.5.1.
  • CVE-2026-30930: Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string concatenation with unsanitized system monitoring data. The normalize() method wraps string values in single quotes but does not escape embedded single quotes, making SQL injection trivial via attacker-controlled data such as process names, filesystem mount points, network interface names, or container names. This vulnerability is fixed in 4.5.1.
Created: 2026-03-11 Last update: 2026-03-12 16:30
2 security issues in forky high

There are 2 open security issues in forky.

2 important issues:
  • CVE-2026-30928: Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint returns the entire parsed Glances configuration file (glances.conf) via self.config.as_dict() with no filtering of sensitive values. The configuration file contains credentials for all configured backend services including database passwords, API tokens, JWT signing keys, and SSL key passwords. This vulnerability is fixed in 4.5.1.
  • CVE-2026-30930: Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string concatenation with unsanitized system monitoring data. The normalize() method wraps string values in single quotes but does not escape embedded single quotes, making SQL injection trivial via attacker-controlled data such as process names, filesystem mount points, network interface names, or container names. This vulnerability is fixed in 4.5.1.
Created: 2026-03-11 Last update: 2026-03-12 16:30
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.3 instead of 4.7.2).
Created: 2025-12-23 Last update: 2025-12-23 20:00
news
[rss feed]
  • [2025-09-03] glances 4.3.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-09-01] Accepted glances 4.3.3+dfsg-1 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2025-04-02] glances 4.3.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-29] Accepted glances 4.3.1+dfsg-1 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2025-03-09] glances 4.3.0.8+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-05] glances REMOVED from testing (Debian testing watch)
  • [2025-01-11] glances 4.3.0.8+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-01-08] Accepted glances 4.3.0.8+dfsg-1 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2024-12-22] glances 4.2.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-12-20] Accepted glances 4.2.1+dfsg-1 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2024-11-30] glances 4.1.2.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-10-12] Accepted glances 4.1.2.1+dfsg-1 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2024-05-22] glances 4.0.5+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-05-20] Accepted glances 4.0.5+dfsg-1 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2023-07-12] glances 3.4.0.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-07-12] glances 3.4.0.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-07-09] Accepted glances 3.4.0.3+dfsg-1 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2023-01-25] glances 3.3.1.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-01-23] Accepted glances 3.3.1.1+dfsg-1 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2022-10-26] glances 3.3.0.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-10-23] Accepted glances 3.3.0.1+dfsg-1 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2022-10-17] glances 3.2.5+dfsg-1.1 MIGRATED to testing (Debian testing watch)
  • [2022-10-15] Accepted glances 3.2.5+dfsg-1.1 (source) into unstable (Michael Biebl)
  • [2022-04-19] glances 3.2.5+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-04-17] Accepted glances 3.2.5+dfsg-1 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2022-01-18] Accepted glances 3.2.4.2+dfsg-1~bpo11+1 (source all) into bullseye-backports, bullseye-backports (Debian FTP Masters) (signed by: Boyuan Yang)
  • [2021-12-22] glances 3.2.4.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2021-12-19] Accepted glances 3.2.4.2+dfsg-1 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2021-11-12] glances 3.2.3.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2021-11-10] Accepted glances 3.2.3.1+dfsg-1 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • 1
  • 2
bugs [bug history graph]
  • all: 9
  • RC: 2
  • I&N: 5
  • M&W: 2
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 4.3.3+dfsg-1
  • 12 bugs (1 patch)

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing