CVE-2026-32253: Lizardbyte Sunshine

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom verify callback treats X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY, X509_V_ERR_CERT_NOT_YET_VALID, and X509_V_ERR_CERT_HAS_EXPIRED as success. This can allow an untrusted certificate to pass authentication and access protected HTTPS endpoints. This issue has been fixed in version 2026.516.143833.

Affected products

  • Lizardbyte Sunshine: before 2026.516.143833 (fixed in 2026.516.143833)

Published 2026-05-22. Last modified 2026-07-23.