CVE-2023-43644: Sagernet Sing-Box
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafted requests are sent to sing-box. This affects all SOCKS5 inbounds with user authentication and an attacker may be able to bypass authentication. Users are advised to update to sing-box 1.4.4 or to 1.5.0-rc.4. Users unable to update should not expose the SOCKS5 inbound to insecure environments.
Affected products
- Sagernet Sing-Box: before 1.4.5 (fixed in 1.4.5); version 1.5.0 only
Published 2023-09-25. Last modified 2026-06-17.