Part of a story covered by 2 sources: “xdg-dbus-proxy: two vulnerabilities disclosed — broadcast filtering bypass (CVE-2026-93676) and sandbox escape (CVE-2026-94422) fixed in 0.1.9” — merged summary and timeline →
xdg-dbus-proxy 0.1.9 fixes sandbox escape CVE-2026-94422
AI summary · grok-4.7
xdg-dbus-proxy 0.1.9 patches sandbox escape CVE-2026-94422; every older release is vulnerable.
Simon McVittie announced on oss-security that xdg-dbus-proxy 0.1.9 fixes CVE-2026-94422, a sandbox escape. All versions older than 0.1.9 are vulnerable. The fix is documented in GitHub advisory GHSA-2cgv-pwcq-wvpq and the 0.1.9 release notes. The notice does not report active exploitation.
- CVE-2026-94422 is a sandbox escape in xdg-dbus-proxy.
- Version 0.1.9 fixes it; every older release is vulnerable.
- The GitHub advisory is GHSA-2cgv-pwcq-wvpq.
- The notice does not report active exploitation.
VendorsFlatpak
Productsxdg-dbus-proxy
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-94422 | NVD description · AI analysis pending | — | — | — | — | — |
Full article
Posted by Simon McVittie on Sep 23 xdg-dbus-proxy 0.1.9 fixes a security vulnerability, CVE-2026-94422: https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-2cgv-pwcq-wvpq> https://github.com/flatpak/xdg-dbus-proxy/releases/tag/0.1.9> All versions older than 0.1.9 are vulnerable.
This source does not provide full text. Read it at seclists.org.