CVE-2026-79574
nicheUnauthenticated Code Injection in mpush Gateway Server 0.8.1
The gateway server component of the open-source mpush push-messaging framework, version 0.8.1, contains a code-injection flaw (CWE-94) that allows remote attackers to execute arbitrary code by sending a specially crafted broadcast message. The vector requires no privileges or user interaction (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N), so any party able to reach the gateway's message interface can potentially trigger it. Successful exploitation yields arbitrary code execution on the gateway host, giving the attacker control of the push service and access to the message traffic it handles. Only deployments running the mpush 0.8.1 gateway server are cited as affected, and no patched release is specified in the available data. There is no known public PoC, the flaw is not in CISA KEV, and EPSS is low (~0.2%), so exploitation in the wild is not yet documented.
What to do: Inventory your environment for mpush gateway servers running 0.8.1 and restrict network access to the gateway/broadcast message interface to trusted senders only (firewall or ACL rules) until an upstream fix is available. Monitor the project's code repository for a patched release and upgrade promptly when one is published; given the critical CVSS score but low EPSS, prioritize confirming whether any gateway instance is internet-exposed.
| mpush (open-source project) mpush gateway server | 0.8.1 (the only version cited; no fix version or prior-version range given in the data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.