Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4542-1 | xdg-dbus-proxy security update |
Debian DSA |
DSA-6209-1 | xdg-dbus-proxy security update |
Debian DSA |
DSA-6224-1 | xdg-dbus-proxy security update |
Ubuntu USN |
USN-8167-1 | xdg-dbus-proxy vulnerability |
Tue, 21 Apr 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 14 Apr 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:flatpak:xdg-dbus-proxy:*:*:*:*:*:*:*:* |
Sat, 11 Apr 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 08 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flatpak
Flatpak xdg-dbus-proxy |
|
| Vendors & Products |
Flatpak
Flatpak xdg-dbus-proxy |
Wed, 08 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Apr 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1286 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 07 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar cases. Clients can intercept D-Bus messages they should not have access to. This vulnerability is fixed in 0.1.7. | |
| Title | xdg-dbus-proxy has an eavesdrop filter bypass allowing message interception | |
| Weaknesses | CWE-1289 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-21T12:21:20.635Z
Reserved: 2026-03-25T16:21:40.868Z
Link: CVE-2026-34080
Updated: 2026-04-21T12:21:20.635Z
Status : Modified
Published: 2026-04-07T21:17:17.720
Modified: 2026-04-21T13:16:20.243
Link: CVE-2026-34080
OpenCVE Enrichment
Updated: 2026-04-15T16:15:11Z
Debian DLA
Debian DSA
Ubuntu USN