Vulnerability in Discord libdave Affects Audio and Video Encryption
CVE-2026-104480

9.4CRITICAL

Key Information:

Vendor

Discord

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104480?

The Discord libdave library, prior to version 1.2.0, suffers from an improper validation vulnerability that allows potential attackers to exploit the MLS Welcome message response. If the group's roster includes participants that are not recognized, the library fails to reject them. This flaw presents an opportunity for an attacker controlling the DAVE signaling path to insert unauthorized members into the audio and video sessions, jeopardizing the confidentiality and integrity of communications. The issue underscores the importance of stringent validation mechanisms in ensuring secure end-to-end encrypted media exchanges.

Affected Version(s)

libdave 1.1.0 < 1.2.0

libdave 7b15f1fc16f159da0478aa6be909e38f1e957833 < 9686fbaea864aa19f0675e486672b6a77811b6a1

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MDL (https://heartbreak.ing)
.