Medium severity6.3NVD Advisory· Published Jul 29, 2021· Updated Jun 17, 2026
CVE-2021-23418
CVE-2021-23418
Description
The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is known to be vulnerable to XML attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
GlancesPyPI | < 3.2.1 | 3.2.1 |
Affected products
4- ghsa-coords2 versions
< 3.2.1+ 1 more
- (no CPE)range: < 3.2.1
- (no CPE)range: < 4.5.6-1.1
Patches
Vulnerability mechanics
References
8- github.com/nicolargo/glances/commit/4b87e979afdc06d98ed1b48da31e69eaa3a9fb94nvdPatchThird Party AdvisoryWEB
- github.com/nicolargo/glances/commit/85d5a6b4af31fcf785d5a61086cbbd166b40b07anvdPatchThird Party AdvisoryWEB
- github.com/nicolargo/glances/commit/9d6051be4a42f692392049fdbfc85d5dfa458b32nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-PYTHON-GLANCES-1311807nvdPatchThird Party AdvisoryWEB
- github.com/nicolargo/glances/issues/1025nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-r2mj-8wgq-73m6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23418ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/glances/PYSEC-2021-115.yamlghsaWEB
News mentions
0No linked articles in our index yet.