9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom verify callback treats X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY, X509_V_ERR_CERT_NOT_YET_VALID, and X509_V_ERR_CERT_HAS_EXPIRED as success. This can allow an untrusted certificate to pass authentication and access protected HTTPS endpoints. This issue has been fixed in version 2026.516.143833.
AI Analysis
Authentication bypass via improper client certificate validation in Sunshine game stream host
Basic Information
ID
CVE-2026-32253
Source
GitHub_M
Published
May 22, 2026 at 17:07
Affected Product
Vendor
LizardByte
Product
Sunshine
Version
< 2026.516.143833
Affected Versions
LizardByte Sunshine < 2026.516.143833
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
LizardByte
Product
Sunshine
Version
< 2026.516.143833