Skip to main content

Vendor/product archive

lizardbyte / sunshine CVEs

Beta · best-effort

11 CVEs tagged to lizardbyte / sunshine2 Critical, 4 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-32253

Published May 22, 2026

Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verifi…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-54081

Published Sep 23, 2025

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If Su…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-10199

Published Sep 9, 2025

A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior versions) due to an unquoted service path.

CVSS 7.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-10198

Published Sep 9, 2025

Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers to insert a malicious DLL in user-writeable PATH directorie…

CVSS 7.8 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-53096

Published Jul 1, 2025

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53095

Published Jul 1, 2025

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Forgery (CSRF) attacks…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-51738

Published Jan 20, 2025

Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementation does not validate request order and is thereby vulnerab…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45407

Published Sep 10, 2024

Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing process may inadvertantly allow access to an unintended client r…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31226

Published May 16, 2024

Sunshine is a self-hosted game stream host for Moonlight. Users who ran Sunshine versions 0.17.0 through 0.22.2 as a service on Windows may be impacted when terminating the servic…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31221

Published Apr 8, 2024

Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pair…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31220

Published Apr 5, 2024

Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.16.0 and prior to version 0.18.0, an attacker may be able to remotely read arbitrary files without…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1