CVE-2026-30930: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-30930 is a SQL injection vulnerability in the TimescaleDB export module of Glances, an open-source cross-platform system monitoring tool. The flaw exists in all versions prior to 4.5.1 (specifically confirmed in 4.5.0) and was published on March 10, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 7.3 (High) (GitHub Advisory, Red Hat).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The vulnerable normalize() method in glances/exports/glances_timescaledb/__init__.py wraps string values in single quotes using f"'{value}'" without escaping embedded single quotes, and the resulting strings are concatenated directly into INSERT queries executed via cur.execute() — no parameterized queries are used. An attacker can control input through process names, filesystem mount points, network interface names, or container names, injecting arbitrary SQL that is executed against the TimescaleDB (PostgreSQL) backend. The fix in version 4.5.1 replaces string concatenation with psycopg.sql parameterized queries and sql.Identifier/sql.Placeholder constructs throughout the export module (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an attacker to execute arbitrary SQL commands against the TimescaleDB/PostgreSQL database backing Glances, enabling data destruction (DROP TABLE, DELETE, TRUNCATE), data exfiltration (via COPY ... TO or subqueries), and potential remote code execution via PostgreSQL extensions such as COPY ... PROGRAM. Any local user who can create a process with a crafted name can inject SQL, potentially compromising the entire PostgreSQL instance and enabling privilege escalation within the database environment (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, providing exact payloads and step-by-step reproduction instructions against a real Glances deployment. The CVSS v4.0 exploit maturity is rated PROOF_OF_CONCEPT. The EPSS score is approximately 0.016% (0.000160), indicating low current exploitation probability. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Detection is available via Nessus plugin 301848 (GitHub Advisory, Tenable).

Exploitation steps

  1. Identify target: Confirm the target system is running Glances version prior to 4.5.1 with the TimescaleDB export module enabled and connected to a PostgreSQL/TimescaleDB instance.
  2. Craft malicious process name: As a local (non-root) user on the monitored system, create a process whose name contains a SQL injection payload. For example:
    exec -a "x'); COPY (SELECT version()) TO '/tmp/sqli_proof.txt' --" python3 -c 'import time; [sum(range(500000)) or time.sleep(0.01) for _ in iter(int, 1)]'
  3. Trigger Glances export: Wait for or trigger Glances (running as root or a privileged user) to collect process metrics and export them to TimescaleDB:
    glances --export timescaledb --export-process-filter ".*" --time 5 --stdout cpu
  4. SQL injection executes: Glances collects the malicious process name, passes it through the unescaped normalize() function, and concatenates it into an INSERT query. The injected SQL breaks out of the string literal and executes the attacker-controlled statement against the database.
  5. Verify/escalate: Confirm execution (e.g., check for /tmp/sqli_proof.txt). Escalate by using COPY ... PROGRAM for OS command execution, or exfiltrate/destroy database contents (GitHub Advisory).

Indicators of compromise

  • Process: Unusual processes with names containing SQL syntax characters (single quotes, semicolons, SQL keywords like COPY, DROP, SELECT, INSERT) visible in process listings or Glances logs.
  • File System: Unexpected files created in /tmp or other world-writable directories (e.g., /tmp/sqli_proof.txt) owned by the PostgreSQL service account, indicating successful COPY ... TO execution.
  • Logs: Glances debug logs (--stdout or log file) showing INSERT queries containing unescaped SQL syntax; PostgreSQL logs recording unexpected COPY, DROP, or SELECT statements originating from the Glances database user.
  • Database: Unexpected tables dropped or truncated; new files written by the PostgreSQL process; unusual COPY ... PROGRAM entries in PostgreSQL's pg_stat_activity or audit logs (GitHub Advisory).

Mitigation and workarounds

Upgrade Glances to version 4.5.1 or later, which replaces all vulnerable string-concatenated SQL with parameterized queries using psycopg.sql (Glances Release, Patch Commit). If immediate patching is not possible, restrict network access to the Glances monitoring tool and its TimescaleDB backend to trusted internal networks only, and disable the TimescaleDB export module. Additionally, apply least-privilege principles to the database user account used by Glances to limit the impact of any successful injection (GitHub Advisory).

Community reactions

The vulnerability was reported by researchers theamanrawat and neo-ai-engineer and acknowledged by the Glances maintainer (nicolargo), who released the fix in version 4.5.1 on March 7, 2026. Red Hat tracked the issue via Bugzilla (Bug 2446050) and rated it high severity. The CVE received automated coverage from vulnerability tracking services including VulDB and Bluesky CVE feeds shortly after disclosure (Red Hat Bugzilla, GitHub Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

glances

Fixed

sid

glances: 4.5.1+dfsg-1

Fixed

trixie

glances

Fixed

Ubuntu

Unknown

bionic (esm-apps)

glances

Unknown

devel

glances

Unknown

focal (esm-apps)

glances

Unknown

jammy

glances

Unknown

jammy (esm-apps)

glances

Unknown

noble

glances

Unknown

noble (esm-apps)

glances

Unknown

resolute

glances

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management