Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-94422: xdg-dbus-proxy lets sandboxed apps escape

CVE-2026-94422 · published today
Summary

The xdg-dbus-proxy component used in Debian, Ubuntu, Fedora and Red Hat Enterprise Linux 9/10 can be tricked into passing messages it should block, allowing a compromised Flatpak or similar app to run code outside its sandbox. This risk exists in all versions before 0.1.9. Update xdg-dbus-proxy to version 0.1.9 or later to close the gap.

What to do
  • Update debian xdg-dbus-proxy to version 0.1.6-1+deb13u3.
  • Update debian xdg-dbus-proxy to version 0.1.9-1.
  • Update fedora fedora to version 0.1.9 or later.
Affected software
Ecosystem VendorProductAffected versions
Debian:12 debian xdg-dbus-proxy All versions
Debian:13 debian xdg-dbus-proxy < 0.1.6-1+deb13u3
Fix: upgrade to 0.1.6-1+deb13u3
Debian:14 debian xdg-dbus-proxy < 0.1.9-1
Fix: upgrade to 0.1.9-1
Ubuntu:Pro:20.04:LTS canonical xdg-dbus-proxy All versions
– fedora fedora < 0.1.9
– red hat red hat enterprise linux 9 All versions
– red hat red hat enterprise linux 10 All versions
Original advisory text
xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape
An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.
Severity
9.9 Critical
Type
CWE-290Authentication Bypass by Spoofing
Timeline
Published2 Oct 2026
Updated3 Oct 2026
First seen23 Sep 2026
Track software like this
Free during beta