← Vulnerability feed

Vulnerability record · CVE-2026-32253 · published 22 May 2026

CVE-2026-32253: Lizardbyte sunshine improper authentication vulnerability

Lizardbyte · Sunshine

Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom verify callback treats X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY, X509_V_ERR_CERT_NOT_YET_VALID, and X509_V_ERR_CERT_HAS_EXPIRED as success. This can allow an untrusted certificate to pass authentication and access protected HTTPS endpoints. This issue has been fixed in version 2026.516.143833.

9.8 CVSS 3.1 Critical EPSS 0.43% · top 65.3% CWE-287 · Improper authenticationCWE-295 · Improper certificate validation
9.8CVSS 3.1 base score
0.43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
23 Jul 2026Last modified by NVD

Description

Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom verify callback treats X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY, X509_V_ERR_CERT_NOT_YET_VALID, and X509_V_ERR_CERT_HAS_EXPIRED as success. This can allow an untrusted certificate to pass authentication and access protected HTTPS endpoints. This issue has been fixed in version 2026.516.143833.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-32253 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-53095Lizardbyte sunshine cross-site request forgery vulnerabilitySunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site …EPSS 0.23%7.8CVE-2025-10199Lizardbyte sunshine unquoted search path vulnerabilityA local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior versions) due to an unquoted ser…EPSS 0.18%7.8CVE-2025-10198Lizardbyte sunshine uncontrolled search path element vulnerabilitySunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers to insert a malicious DLL in …EPSS 0.22%7.7CVE-2024-51738Lizardbyte sunshine null pointer dereference vulnerabilitySunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementation does not validate request…EPSS 0.58%7.3CVE-2024-31220Lizardbyte sunshine path traversal vulnerabilitySunshine is a self-hosted game stream host for Moonlight. Starting in version 0.16.0 and prior to version 0.18.0, an attacker may be able to remotely…EPSS 0.49%7.0CVE-2025-54081Lizardbyte sunshine unquoted search path vulnerabilitySunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an u…EPSS 0.23%6.1CVE-2025-53096Lizardbyte sunshine clickjacking vulnerabilitySunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjackin…EPSS 0.22%5.9CVE-2024-31221Lizardbyte sunshine vulnerabilitySunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the …EPSS 0.51%

Source: NIST National Vulnerability Database (record CVE-2026-32253), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.