CVE-2026-34080: xdg-dbus-proxy has an eavesdrop filter bypass allowing message interception
Last updated 27 May 2026
Other sources
xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar cases. Clients can intercept D-Bus messages they should not have access to. This vulnerability is fixed in 0.1.7.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/xdg-dbus-proxyto a version that resolves this vulnerability.Fixed in 0.1.2-2+deb11u1Fixed in 0.1.4-3+deb12u1Fixed in 0.1.6-1+deb13u1Fixed in 0.1.7-1 - Upgrade
Upgrade
xdg-dbus-proxyto a version that resolves this vulnerability.Fixed in 0.1.7Patch CVE-2026-34080
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34080?
CVE-2026-34080 has been classified as a high-severity vulnerability due to its ability to allow message interception.
How do I fix CVE-2026-34080?
To fix CVE-2026-34080, upgrade xdg-dbus-proxy to version 0.1.7 or later.
What are the potential impacts of CVE-2026-34080?
CVE-2026-34080 can lead to unauthorized access to sensitive communication between D-Bus applications.
Who is affected by CVE-2026-34080?
CVE-2026-34080 affects users of xdg-dbus-proxy versions prior to 0.1.7.
What type of vulnerability is CVE-2026-34080?
CVE-2026-34080 is a policy parser vulnerability specifically affecting the eavesdrop filter in xdg-dbus-proxy.