Lizardbyte develops Sunshine, a widely deployed remote-desktop and game-streaming application that facilitates multi-user access to local systems. The recurring vulnerability patterns center on authentication and channel-access issues—including authentication bypass, unquoted search paths, CSRF, and improper authentication mechanisms—which reflect the complexity of securing multi-endpoint streaming and credential handling in a desktop-bridging tool. A meaningful share of the vendor's disclosures reach serious severity; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lizardbyte over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32253CRITICAL Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verific | May 22, 2026 | 9.8 | 36 | NO | NO |
CVE-2025-10199HIGH A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior versions) due to an unquoted service path. | Sep 9, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-10198HIGH Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers to insert a malicious DLL in user-writeable PATH directories | Sep 9, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-53095HIGH Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Forgery (CSRF) attacks. | Jul 1, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-54081HIGH Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If Sun | Sep 23, 2025 | 7.0 | 23 | NO | NO |
CVE-2024-51738HIGH Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementation does not validate request order and is thereby vulnerabl | Jan 20, 2025 | 8.1 | 22 | NO | NO |
CVE-2024-31220HIGH Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.16.0 and prior to version 0.18.0, an attacker may be able to remotely read arbitrary files without a | Apr 5, 2024 | 7.3 | 21 | NO | NO |
CVE-2025-53096MEDIUM Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability a | Jul 1, 2025 | 6.1 | 19 | NO | NO |
CVE-2024-45407MEDIUM Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing process may inadvertantly allow access to an unintended client ra | Sep 10, 2024 | 5.3 | 16 | NO | NO |
CVE-2024-31221MEDIUM Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pairi | Apr 8, 2024 | 5.9 | 16 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lizardbyte.
Media articles that mention a CVE ID that affects a product developed by Lizardbyte — matched by CVE ID, not by vendor name.