GLib vulnerability

A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.

Published 30 Jun 2026Updated 9 Sep 202621 sources
CVSS 5.9 ✓ VERIFIED REFERENCE

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.