CVE 9.8 CRITICAL

Sunshine: Authentication bypass via improper client certificate validation_CVE-2026-32253

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom verify callback treats X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY, X509_V_ERR_CERT_NOT_YET_VALID, and X509_V_ERR_CERT_HAS_EXPIRED as success. This can allow an untrusted certificate to pass authentication and access protected HTTPS endpoints. This issue has been fixed in version 2026.516.143833.

AI Analysis

Authentication bypass via improper client certificate validation in Sunshine game stream host

Basic Information

ID CVE-2026-32253
Source GitHub_M
Published May 22, 2026 at 17:07

Affected Product

Vendor LizardByte
Product Sunshine
Version < 2026.516.143833
Affected Versions LizardByte Sunshine < 2026.516.143833

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor LizardByte
Product Sunshine
Version < 2026.516.143833

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.