CVE-2026-32634: Glances Zeroconf Credential Leak

Lookup of locally saved credentials or URI construction using an untrusted mDNS server name. An attacker can spoof the Zeroconf broadcast to extract saved credentials.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-32634-glances-zeroconf-credential-leak --engine opengrep

Description

Lookup of locally saved credentials or URI construction using an untrusted mDNS server name. An attacker can spoof the Zeroconf broadcast to extract saved credentials.