ZeroHour

CVE-2026-79574

niche

Unauthenticated Code Injection in mpush Gateway Server 0.8.1

CVSS 3.1
9.8 critical
EPSS
<1%p40
Published
()
Modified
AI analysis

The gateway server component of the open-source mpush push-messaging framework, version 0.8.1, contains a code-injection flaw (CWE-94) that allows remote attackers to execute arbitrary code by sending a specially crafted broadcast message. The vector requires no privileges or user interaction (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N), so any party able to reach the gateway's message interface can potentially trigger it. Successful exploitation yields arbitrary code execution on the gateway host, giving the attacker control of the push service and access to the message traffic it handles. Only deployments running the mpush 0.8.1 gateway server are cited as affected, and no patched release is specified in the available data. There is no known public PoC, the flaw is not in CISA KEV, and EPSS is low (~0.2%), so exploitation in the wild is not yet documented.

What to do: Inventory your environment for mpush gateway servers running 0.8.1 and restrict network access to the gateway/broadcast message interface to trusted senders only (firewall or ACL rules) until an upstream fix is available. Monitor the project's code repository for a patched release and upgrade promptly when one is published; given the critical CVSS score but low EPSS, prioritize confirming whether any gateway instance is internet-exposed.

Affected
mpush (open-source project) mpush gateway server0.8.1 (the only version cited; no fix version or prior-version range given in the data)
Estimated exposure
nichelikely hundreds to low thousands of self-hosted deployments (unknown precisely) — mpush is a niche open-source push-messaging framework with no published install or usage metrics, so exposure is assumed to be limited to a small population of self-hosted gateway deployments, some of which may be internet-facing.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.

Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.