Lizardbyte
Lizardbyte Sunshine: vulnerabilities and CVEs
Lizardbyte Sunshine has 11 published vulnerabilities, 1 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs11
Last 12 months1
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32253 | Critical (9.8) | 0.43% | — | May 22, 2026 | Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In… |
| CVE-2025-54081 | High (7) | 0.23% | — | Sep 23, 2025 | Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If Sunshine is installed in a directory whose… |
| CVE-2025-10199 | High (7.8) | 0.19% | — | Sep 9, 2025 | A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior versions) due to an unquoted service path. |
| CVE-2025-10198 | High (7.8) | 0.22% | — | Sep 9, 2025 | Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers to insert a malicious DLL in user-writeable PATH directories. |
| CVE-2025-53096 | Medium (6.1) | 0.22% | — | Jul 1, 2025 | Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability allows an attacker to embed the Sunshine… |
| CVE-2025-53095 | High (8.8) | 0.23% | — | Jul 1, 2025 | Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Forgery (CSRF) attacks. This vulnerability allows an attacker… |
| CVE-2024-51738 | High (7.7) | 0.58% | — | Jan 20, 2025 | Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementation does not validate request order and is thereby vulnerable to a MITM attack, potentially… |
| CVE-2024-45407 | Medium (5.3) | 0.34% | — | Sep 10, 2024 | Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing process may inadvertantly allow access to an unintended client rather than failing authentication due to… |
| CVE-2024-31226 | Low (2.9) | 0.22% | — | May 16, 2024 | Sunshine is a self-hosted game stream host for Moonlight. Users who ran Sunshine versions 0.17.0 through 0.22.2 as a service on Windows may be impacted when terminating the service if an attacked placed a file named… |
| CVE-2024-31221 | Medium (5.9) | 0.51% | — | Apr 8, 2024 | Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pairing only one device, all of the… |
| CVE-2024-31220 | High (7.3) | 0.49% | — | Apr 5, 2024 | Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.16.0 and prior to version 0.18.0, an attacker may be able to remotely read arbitrary files without authentication due to a path traversal… |