CVE-2026-63409

Source
https://cve.org/CVERecord?id=CVE-2026-63409
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63409.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63409
Aliases
  • GHSA-gmvh-3c73-m5gg
Downstream
Published
2026-08-17T20:57:19.326Z
Modified
2026-08-20T10:17:20.788636Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H CVSS Calculator
Summary
Deskflow: Odd-length DSOP options vector causes out-of-bounds read in Deskflow client
Details

Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP vector to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp, causing the missing value after the final option key to be read beyond the vector during the PacketStreamFilter::filterEvent to ServerProxy::handleData() to ServerProxy::parseHandshakeMessage() call chain and crash the connected client. This issue is fixed in continuous build 1.26.0.296.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63409.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.17.0"
                },
                {
                    "fixed": "1.26.0.296"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-125"
    ]
}
References

Affected packages

Git / github.com/deskflow/deskflow

Affected ranges

Type
GIT
Repo
https://github.com/deskflow/deskflow
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

v1.*
v1.17.0
v1.17.1
v1.17.2
v1.18.0
v1.19.0
v1.20.0
v1.20.1
v1.21.0
v1.21.1
v1.21.2
v1.22.0
v1.23.0
v1.24.0
v1.25.0
v1.26.0

Database specific

vanir_signatures_modified
"2026-08-20T10:17:20Z"
vanir_signatures
[
    {
        "id": "CVE-2026-63409-03a42dcc",
        "target": {
            "file": "src/lib/server/ClientProxy1_0.cpp"
        },
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "59296496970081143490392020132113578308",
                "264147184473189989835777453027769399669",
                "105461901912855228587267469831660350127",
                "84147866730353443619115107668400347161"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "deprecated": false,
        "source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
    },
    {
        "id": "CVE-2026-63409-11dad1d3",
        "target": {
            "file": "src/lib/client/Client.cpp"
        },
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "236976754671402044676543928600241033718",
                "301820332396168299652958655454656578282",
                "75656020767226221753543808461534719015",
                "88737114258928579320783421213981706439"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "deprecated": false,
        "source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
    },
    {
        "id": "CVE-2026-63409-40e33c37",
        "target": {
            "file": "src/lib/deskflow/Screen.cpp"
        },
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "93452003649932511260159433311084409086",
                "247688328563674058561963965487937275917",
                "222930386684317508431460109957809265988",
                "28762715122451522537557181752956634048"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "deprecated": false,
        "source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
    },
    {
        "id": "CVE-2026-63409-4211de9e",
        "target": {
            "file": "src/lib/platform/XWindowsScreen.cpp",
            "function": "XWindowsScreen::setOptions"
        },
        "signature_version": "v1",
        "digest": {
            "length": 529.0,
            "function_hash": "242150540230015351880935572870261266256"
        },
        "signature_type": "Function",
        "deprecated": false,
        "source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
    },
    {
        "id": "CVE-2026-63409-57e2ac2f",
        "target": {
            "file": "src/lib/client/ServerProxy.cpp",
            "function": "ServerProxy::setOptions"
        },
        "signature_version": "v1",
        "digest": {
            "length": 1125.0,
            "function_hash": "46660015884301948534165028696470585037"
        },
        "signature_type": "Function",
        "deprecated": false,
        "source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
    },
    {
        "id": "CVE-2026-63409-6859f86c",
        "target": {
            "file": "src/lib/client/ServerProxy.cpp"
        },
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "34153358309916817461995184018916692635",
                "177866724128377571376130959453194049113",
                "170436926807622728606035106478103507819"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "deprecated": false,
        "source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
    },
    {
        "id": "CVE-2026-63409-7d19d0e5",
        "target": {
            "file": "src/lib/client/Client.cpp",
            "function": "Client::setOptions"
        },
        "signature_version": "v1",
        "digest": {
            "length": 915.0,
            "function_hash": "312139493942473756410202906392974875075"
        },
        "signature_type": "Function",
        "deprecated": false,
        "source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
    },
    {
        "id": "CVE-2026-63409-929b8799",
        "target": {
            "file": "src/lib/server/ClientProxy1_0.cpp",
            "function": "ClientProxy1_0::setOptions"
        },
        "signature_version": "v1",
        "digest": {
            "length": 541.0,
            "function_hash": "104530485550888798731996742964881974822"
        },
        "signature_type": "Function",
        "deprecated": false,
        "source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
    },
    {
        "id": "CVE-2026-63409-a61be1d9",
        "target": {
            "file": "src/lib/deskflow/Screen.cpp",
            "function": "Screen::setOptions"
        },
        "signature_version": "v1",
        "digest": {
            "length": 1080.0,
            "function_hash": "18947052360808800384892180812294548188"
        },
        "signature_type": "Function",
        "deprecated": false,
        "source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
    },
    {
        "id": "CVE-2026-63409-aa93e63b",
        "target": {
            "file": "src/lib/platform/XWindowsScreen.cpp"
        },
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "273541962625817997133142657194574257165",
                "202300633054273446961833766744508583768",
                "337889412725806583931295026569644801833",
                "26441519965697055416038752529846435248"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "deprecated": false,
        "source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63409.json"