Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pairing only one device, all of the previously devices will be temporarily paired. Version 0.23.0 contains a patch for the issue. As a workaround, restarting Sunshine after unpairing all devices prevents the vulnerability.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-384"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/31xxx/CVE-2024-31221.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-31221.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"201202426796520643551936793339072697682",
"211882367305005862719183239137884205909",
"334647665408801863533416331013220228562"
],
"threshold": 0.9
},
"id": "CVE-2024-31221-02506f3a",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/lizardbyte/sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e",
"target": {
"file": "src/crypto.h"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"1585701933094147099602899156136502084",
"153608806563574501415661689088963927244",
"262576743315697533190530076771836743960",
"173027894629410927525602950600874268803"
],
"threshold": 0.9
},
"id": "CVE-2024-31221-5826f5ba",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/lizardbyte/sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e",
"target": {
"file": "src/crypto.cpp"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"192098890394081933265290257924364621318",
"254241803979571484358740049276357293933",
"288674398846155826663801907126508823055",
"180221748080936969578056972910841304916",
"20628179690645497651863246657203562594",
"16188109359966460146886447391056541555",
"336606211597947748372607915765614896796",
"78448761496726033314037558600892302391",
"213854922846858838315892695396249928895",
"88900426475204953588421285438512710411",
"235880680085989615830160298967034401877",
"180244452180102374882087876126571280623",
"257739832634380958328599261120043821276",
"261467030271407656858693594739908712423",
"159954202103777506778132383144300285864",
"57795368251015756146809741505723002127",
"266905279123735289134377457345511434046",
"163063473316812424156661847251333583931"
],
"threshold": 0.9
},
"id": "CVE-2024-31221-58ec30b4",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/lizardbyte/sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e",
"target": {
"file": "src/nvhttp.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "204325495212323613447422234646413432291",
"length": 4070
},
"id": "CVE-2024-31221-5b0261be",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/lizardbyte/sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e",
"target": {
"file": "src/nvhttp.cpp",
"function": "start"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "280090849978685261762697490636959036782",
"length": 65
},
"id": "CVE-2024-31221-61719b2c",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/lizardbyte/sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e",
"target": {
"file": "src/nvhttp.cpp",
"function": "erase_all_clients"
}
}
]
"2026-08-12T15:15:12Z"