high · CVSS v3 8.8 · CVSS v4 8.7
CVE-2026-94422
An incorrect message filtering implementation in xdg-dbus-proxy allows bypassing D-Bus session bus filters by setting a reply serial number
Overview
An incorrect message filtering implementation in xdg-dbus-proxy allows bypassing D-Bus session bus filters by setting a reply serial number on non-reply messages. This flaw can be exploited by a malicious or compromised Flatpak app to execute code outside its sandbox. The vulnerability affects systems using xdg-dbus-proxy before version 0.1.9.
Description
An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.
Impact
Confidentiality: attackers can read or modify inter-process messages. Integrity: they can alter or inject messages, leading to arbitrary code execution. Availability: potential denial of service by exhausting resources. Defenders include users of Flatpak, Firejail, and any distribution bundling vulnerable xdg-dbus-proxy.
Remediation
Upgrade xdg-dbus-proxy to version 0.1.9 or later. For distributions, apply the vendor’s security update or rebuild the package with the patched source. Disable or restrict D-Bus message filtering for untrusted apps, and enforce strict sandbox boundaries in Flatpak or Firejail configurations.
Risk context
Severity is high with CVSS v3 score 8.8 and v4 score 8.7. No EPSS data is available, but the flaw permits arbitrary code execution, making it a critical issue for affected systems.
Affected products
- xdg-dbus-proxy
- Flatpak
- Firejail
- Linux D-Bus
- Ubuntu
- Fedora
- Debian
- CentOS
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 8.8
- CVSS v4
- 8.7
- EPSS
- —