{"id":"CVE-2024-31221","summary":"Clients removed during unpairing process may regain access if Sunshine was not restarted","details":"Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pairing only one device, all of the previously devices will be temporarily paired. Version 0.23.0 contains a patch for the issue. As a workaround, restarting Sunshine after unpairing all devices prevents the vulnerability.","aliases":["GHSA-v8gw-jw28-v55m"],"modified":"2026-08-12T15:15:12.390352Z","published":"2024-04-08T15:10:17.071Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-384"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/31xxx/CVE-2024-31221.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/31xxx/CVE-2024-31221.json"},{"type":"ADVISORY","url":"https://github.com/LizardByte/Sunshine/security/advisories/GHSA-v8gw-jw28-v55m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-31221"},{"type":"REPORT","url":"https://github.com/LizardByte/Sunshine/issues/2305"},{"type":"FIX","url":"https://github.com/LizardByte/Sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e"},{"type":"FIX","url":"https://github.com/LizardByte/Sunshine/pull/2365"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/lizardbyte/sunshine","events":[{"introduced":"03d572fe103252faf89c35e6c7202390514b65b3"},{"fixed":"14ed89da0e737c4a9b9c1cf8e42ea996d95946be"},{"fixed":"b7aa8119f1471844dccdf73a8b6f7efc9baddb5e"}],"database_specific":{"cpe":"cpe:2.3:a:lizardbyte:sunshine:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.10.0"},{"fixed":"0.23.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v0.22.2","v0.22.1","v0.22.0","v0.21.0","v0.20.0","v0.19.1","v0.19.0","v0.18.4","v0.18.3","v0.18.2","v0.18.1","v0.18.0","v0.17.0","v0.16.0","v0.15.0","v0.14.1","v0.14.0","v0.13.0","v0.12.0","v0.11.1","v0.11.0","v0.10.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-31221.json","vanir_signatures_modified":"2026-08-12T15:15:12Z","vanir_signatures":[{"target":{"file":"src/crypto.h"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["201202426796520643551936793339072697682","211882367305005862719183239137884205909","334647665408801863533416331013220228562"]},"id":"CVE-2024-31221-02506f3a","signature_type":"Line","signature_version":"v1","source":"https://github.com/lizardbyte/sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e"},{"target":{"file":"src/crypto.cpp"},"deprecated":false,"digest":{"line_hashes":["1585701933094147099602899156136502084","153608806563574501415661689088963927244","262576743315697533190530076771836743960","173027894629410927525602950600874268803"],"threshold":0.9},"id":"CVE-2024-31221-5826f5ba","signature_type":"Line","signature_version":"v1","source":"https://github.com/lizardbyte/sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e"},{"id":"CVE-2024-31221-58ec30b4","signature_type":"Line","signature_version":"v1","source":"https://github.com/lizardbyte/sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e","target":{"file":"src/nvhttp.cpp"},"deprecated":false,"digest":{"line_hashes":["192098890394081933265290257924364621318","254241803979571484358740049276357293933","288674398846155826663801907126508823055","180221748080936969578056972910841304916","20628179690645497651863246657203562594","16188109359966460146886447391056541555","336606211597947748372607915765614896796","78448761496726033314037558600892302391","213854922846858838315892695396249928895","88900426475204953588421285438512710411","235880680085989615830160298967034401877","180244452180102374882087876126571280623","257739832634380958328599261120043821276","261467030271407656858693594739908712423","159954202103777506778132383144300285864","57795368251015756146809741505723002127","266905279123735289134377457345511434046","163063473316812424156661847251333583931"],"threshold":0.9}},{"deprecated":false,"digest":{"length":4070,"function_hash":"204325495212323613447422234646413432291"},"id":"CVE-2024-31221-5b0261be","signature_type":"Function","signature_version":"v1","source":"https://github.com/lizardbyte/sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e","target":{"file":"src/nvhttp.cpp","function":"start"}},{"digest":{"function_hash":"280090849978685261762697490636959036782","length":65},"id":"CVE-2024-31221-61719b2c","signature_type":"Function","signature_version":"v1","source":"https://github.com/lizardbyte/sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e","target":{"file":"src/nvhttp.cpp","function":"erase_all_clients"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L"}]}