CVE-2026-34080 Details
Description
xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar cases. Clients can intercept D-Bus messages they should not have access to. This vulnerability is fixed in 0.1.7.
A policy parser vulnerability in xdg-dbus-proxy versions prior to 0.1.7 allows clients to bypass eavesdrop restrictions and intercept D-Bus messages they should not have access to. The proxy incorrectly processes the eavesdrop policy rule, failing to recognize variations such as 'eavesdrop ='true'' (with a space before the equals sign). This vulnerability is fixed in version 0.1.7.
Users are advised to update xdg-dbus-proxy to version 0.1.7 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.debian.org/debian-lts-announce/2026/04/msg00022.html | CVE | |
| http://www.openwall.com/lists/oss-security/2026/04/10/15 | CVE | Third Party Advisory |
| https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-vjp5-hjfm-7677 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-1289 | Improper Validation of Unsafe Equivalence in Input | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| flatpak xdg-dbus-proxy | < 0.1.7 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | CVE Modified | CVE |
| Apr 14, 2026 | Initial Analysis | [email protected] |
| Apr 11, 2026 | CVE Modified | CVE |
| Apr 7, 2026 | New CVE Received | [email protected] |