Description
An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.
Published: 2026-10-02
Score: 8.7 High
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No solution or workaround provided in the CVE record.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6510-1 xdg-dbus-proxy security update
History

Fri, 02 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
References

Fri, 02 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.
Title xdg-dbus-proxy: xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Mon, 28 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Flatpak
Flatpak xdg-dbus-proxy
Vendors & Products Flatpak
Flatpak xdg-dbus-proxy

Mon, 28 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox.
Title xdg-dbus-proxy: xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape
Weaknesses CWE-290
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Subscriptions

Flatpak Xdg-dbus-proxy
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-02T16:51:40.902Z

Reserved: 2026-09-21T15:32:06.674Z

Link: CVE-2026-94422

cve-icon Vulnrichment

Updated: 2026-10-02T14:12:15.134Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T14:17:12.003

Modified: 2026-10-02T18:44:11.270

Link: CVE-2026-94422

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-23T13:57:20Z

Links: CVE-2026-94422 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T16:15:08Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing