CVE-2026-104480
Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video.
| CWE | CWE-390 CWE-863 |
| Vendor | discord |
| Product | libdave |
| Published | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for discord libdave
Be the first to know when new unknown vulnerabilities affecting discord libdave are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Discord / libdave
1.1.0 < 1.2.0 7b15f1fc16f159da0478aa6be909e38f1e957833 < 9686fbaea864aa19f0675e486672b6a77811b6a1
References
Credits
MDL (https://heartbreak.ing)