CVE-2026-104480

Source
https://cve.org/CVERecord?id=CVE-2026-104480
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104480.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-104480
Published
2026-10-02T02:17:02Z
Modified
2026-10-04T02:45:59Z
Severity
  • 9.4 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video.

References

Affected packages

Git / github.com/discord/libdave

Affected ranges

Type
GIT
Repo
https://github.com/discord/libdave
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "1.2.0"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.1.0/cpp
v1.1.1/cpp

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104480.json"