> Debian xdg-dbus-proxy Notable Alert Bypass Vulnerability CVE-2026-94422
[DATE: 23/09/2026 15:57]
[LANGUAGE: EN]
It was discovered that an incorrect implementation of message filtering in xdg-dbus-proxy allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could achieve arbitrary code