xdg-dbus-proxy: two vulnerabilities disclosed — broadcast filtering bypass (CVE-2026-93676) and sandbox escape (CVE-2026-94422) fixed in 0.1.9
Simon McVittie disclosed two xdg-dbus-proxy flaws on oss-security: CVE-2026-93676, a broadcast message filtering bypass, and CVE-2026-94422, a sandbox escape fixed in version 0.1.9; neither is reported as actively exploited.
Two security vulnerabilities in xdg-dbus-proxy were announced on oss-security by Simon McVittie on consecutive days. On 2026-09-22, CVE-2026-93676 was assigned to a broadcast message filtering bypass in xdg-dbus-proxy, also tracked as GitHub advisory GHSA-r7hp-698j-2h6c; that notice only confirmed the identifier and did not describe exploitation or patch details. On 2026-09-23, McVittie announced that xdg-dbus-proxy 0.1.9 fixes CVE-2026-94422, a sandbox escape affecting all versions older than 0.1.9, documented in GitHub advisory GHSA-2cgv-pwcq-wvpq and the 0.1.9 release notes. The two reports describe distinct CVEs in the same project; neither report indicates active exploitation in the wild. No patch version was specified for CVE-2026-93676 in the available reports.
- CVE-2026-93676 is a broadcast message filtering bypass in xdg-dbus-proxy, announced on oss-security on 2026-09-22 and also tracked as GHSA-r7hp-698j-2h6c.
- No patch or exploitation details were provided for CVE-2026-93676 in the report.
- CVE-2026-94422 is a sandbox escape in xdg-dbus-proxy, announced on oss-security on 2026-09-23 and tracked as GHSA-2cgv-pwcq-wvpq.
- xdg-dbus-proxy 0.1.9 fixes CVE-2026-94422; every version older than 0.1.9 is vulnerable.
- Both vulnerabilities were reported by Simon McVittie on the oss-security mailing list.
- Neither vulnerability is reported as being actively exploited.
Coverage timelineoldest first · each row is one article
- · 4d agoRe: xdg-dbus-proxy: GHSA-r7hp-698j-2h6c: broadcast message filtering bypass
oss-security· 44
xdg-dbus-proxy broadcast filtering bypass is now tracked as CVE-2026-93676.
- · 3d agoxdg-dbus-proxy 0.1.9 fixes sandbox escape CVE-2026-94422
oss-security· 61
xdg-dbus-proxy 0.1.9 patches sandbox escape CVE-2026-94422; every older release is vulnerable.
Vulnerabilities in this storyAll →
- CVE-2026-936763.2—D-Bus Broadcast Filtering Bypass in xdg-dbus-proxy Leaks Signals to Flatpak Appspublished · Flatpak project (freedesktop.org) xdg-dbus-proxy
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-93676 |