Skip to content
red-hatCVE-2026-93676

xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions.

Low3.2CVE-2026-93676 · Published Sep 18, 2026 · updated Sep 22, 2026

Source advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Vendor
all versionsNo fix yet
Red Hat Enterprise Linux 9
Vendor
all versionsNo fix yet
Details and references

xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to unauthorized applications.

CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
Severity from
no source yet
Weakness
CWE-284

More red-hat advisories

All
DateAdvisory
Sep 17A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker...
CVE-2026-90997High7.4fixed in Keycloak 26.7.4
Sep 17A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing.
CVE-2026-76781Medium5.5no fix yet
Sep 18A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with...
CVE-2026-89058High7.4fixed in Red Hat, Inc.: CVE records (CNA) 6.2.19.Final, Red Hat, Inc.: CVE records (CNA) 7.0.5.Final
Sep 18A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count.
CVE-2026-89059High7.5fixed in Red Hat, Inc.: CVE records (CNA) 6.2.19.Final, Red Hat, Inc.: CVE records (CNA) 7.0.5.Final
Sep 18A flaw was found in Netty's `netty-handler-ssl-ocsp` component.
CVE-2026-93493Medium5.9no fix yet
Sep 18A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte.
CVE-2026-93494High7.5no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.