CVE-2026-34205 Details
Description
Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network. On Linux, this configuration does not restrict access to the app as intended, allowing any device on the same network to reach these endpoints without authentication. Home Assistant Supervisor 2026.03.02 addresses the issue.
A vulnerability exists in Home Assistant apps configured with host network mode, allowing unauthenticated endpoints to be exposed to the local network via the internal Docker bridge interface. This issue affects Home Assistant Operating System versions through 17.1 and Home Assistant Supervisor versions through 2026.03.1. The vulnerability arises because, on Linux, host network mode shares the host's network namespace without proper firewall restrictions, enabling any device on the same network to access these endpoints without authentication.
Users can update to Home Assistant Supervisor version 2026.03.2, which applies the necessary firewall rules to restrict access to the Docker bridge interface from the local network. A future release of Home Assistant Operating System is also planned to include this fix at the Docker engine level.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/home-assistant/core/security/advisories/GHSA-gh5m-4m97-c95h | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-923 | Improper Restriction of Communication Channel to Intended Endpoints | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 27, 2026 | New CVE Received | [email protected] |