Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP vector to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp, causing the missing value after the final option key to be read beyond the vector during the PacketStreamFilter::filterEvent to ServerProxy::handleData() to ServerProxy::parseHandshakeMessage() call chain and crash the connected client. This issue is fixed in continuous build 1.26.0.296.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63409.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "1.17.0"
},
{
"fixed": "1.26.0.296"
}
],
"source": "AFFECTED_FIELD"
}
],
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-125"
]
}"2026-08-20T10:17:20Z"
[
{
"id": "CVE-2026-63409-03a42dcc",
"target": {
"file": "src/lib/server/ClientProxy1_0.cpp"
},
"signature_version": "v1",
"digest": {
"line_hashes": [
"59296496970081143490392020132113578308",
"264147184473189989835777453027769399669",
"105461901912855228587267469831660350127",
"84147866730353443619115107668400347161"
],
"threshold": 0.9
},
"signature_type": "Line",
"deprecated": false,
"source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
},
{
"id": "CVE-2026-63409-11dad1d3",
"target": {
"file": "src/lib/client/Client.cpp"
},
"signature_version": "v1",
"digest": {
"line_hashes": [
"236976754671402044676543928600241033718",
"301820332396168299652958655454656578282",
"75656020767226221753543808461534719015",
"88737114258928579320783421213981706439"
],
"threshold": 0.9
},
"signature_type": "Line",
"deprecated": false,
"source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
},
{
"id": "CVE-2026-63409-40e33c37",
"target": {
"file": "src/lib/deskflow/Screen.cpp"
},
"signature_version": "v1",
"digest": {
"line_hashes": [
"93452003649932511260159433311084409086",
"247688328563674058561963965487937275917",
"222930386684317508431460109957809265988",
"28762715122451522537557181752956634048"
],
"threshold": 0.9
},
"signature_type": "Line",
"deprecated": false,
"source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
},
{
"id": "CVE-2026-63409-4211de9e",
"target": {
"file": "src/lib/platform/XWindowsScreen.cpp",
"function": "XWindowsScreen::setOptions"
},
"signature_version": "v1",
"digest": {
"length": 529.0,
"function_hash": "242150540230015351880935572870261266256"
},
"signature_type": "Function",
"deprecated": false,
"source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
},
{
"id": "CVE-2026-63409-57e2ac2f",
"target": {
"file": "src/lib/client/ServerProxy.cpp",
"function": "ServerProxy::setOptions"
},
"signature_version": "v1",
"digest": {
"length": 1125.0,
"function_hash": "46660015884301948534165028696470585037"
},
"signature_type": "Function",
"deprecated": false,
"source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
},
{
"id": "CVE-2026-63409-6859f86c",
"target": {
"file": "src/lib/client/ServerProxy.cpp"
},
"signature_version": "v1",
"digest": {
"line_hashes": [
"34153358309916817461995184018916692635",
"177866724128377571376130959453194049113",
"170436926807622728606035106478103507819"
],
"threshold": 0.9
},
"signature_type": "Line",
"deprecated": false,
"source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
},
{
"id": "CVE-2026-63409-7d19d0e5",
"target": {
"file": "src/lib/client/Client.cpp",
"function": "Client::setOptions"
},
"signature_version": "v1",
"digest": {
"length": 915.0,
"function_hash": "312139493942473756410202906392974875075"
},
"signature_type": "Function",
"deprecated": false,
"source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
},
{
"id": "CVE-2026-63409-929b8799",
"target": {
"file": "src/lib/server/ClientProxy1_0.cpp",
"function": "ClientProxy1_0::setOptions"
},
"signature_version": "v1",
"digest": {
"length": 541.0,
"function_hash": "104530485550888798731996742964881974822"
},
"signature_type": "Function",
"deprecated": false,
"source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
},
{
"id": "CVE-2026-63409-a61be1d9",
"target": {
"file": "src/lib/deskflow/Screen.cpp",
"function": "Screen::setOptions"
},
"signature_version": "v1",
"digest": {
"length": 1080.0,
"function_hash": "18947052360808800384892180812294548188"
},
"signature_type": "Function",
"deprecated": false,
"source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
},
{
"id": "CVE-2026-63409-aa93e63b",
"target": {
"file": "src/lib/platform/XWindowsScreen.cpp"
},
"signature_version": "v1",
"digest": {
"line_hashes": [
"273541962625817997133142657194574257165",
"202300633054273446961833766744508583768",
"337889412725806583931295026569644801833",
"26441519965697055416038752529846435248"
],
"threshold": 0.9
},
"signature_type": "Line",
"deprecated": false,
"source": "https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63409.json"