PT-2026-42801 · Lizardbyte · Sunshine

Published

2026-05-22

·

Updated

2026-05-22

·

CVE-2026-32253

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom verify callback treats X509 V ERR UNABLE TO GET ISSUER CERT LOCALLY, X509 V ERR CERT NOT YET VALID, and X509 V ERR CERT HAS EXPIRED as success. This can allow an untrusted certificate to pass authentication and access protected HTTPS endpoints. This issue has been fixed in version 2026.516.143833.

Fix

Improper Certificate Validation

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-32253

Affected Products

Sunshine