Vulnerability in Discord libdave Affects Audio and Video Encryption
CVE-2026-104480
9.4CRITICAL
What is CVE-2026-104480?
The Discord libdave library, prior to version 1.2.0, suffers from an improper validation vulnerability that allows potential attackers to exploit the MLS Welcome message response. If the group's roster includes participants that are not recognized, the library fails to reject them. This flaw presents an opportunity for an attacker controlling the DAVE signaling path to insert unauthorized members into the audio and video sessions, jeopardizing the confidentiality and integrity of communications. The issue underscores the importance of stringent validation mechanisms in ensuring secure end-to-end encrypted media exchanges.
Affected Version(s)
libdave 1.1.0 < 1.2.0
libdave 7b15f1fc16f159da0478aa6be909e38f1e957833 < 9686fbaea864aa19f0675e486672b6a77811b6a1
