CVE-2026-94422: Fedora
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.
Affected products
- Fedora Fedora: before 0.1.9 (fixed in 0.1.9)
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 9
Published 2026-10-02. Last modified 2026-10-02.