Answer in brief
CVE-2026-104480 records a Critical severity (CVSS 9.4) vulnerability in Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership. The current sources do not mark it as known exploited. The current feed maps Discord/discord/libdave (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.4. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Discord/discord/libdave (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Discord/discord/libdavegeneric | >=1.1.0 <1.2.0 || >=7b15f1fc16f159da0478aa6be909e38f1e957833 <9686fbaea864aa19f0675e486672b6a77811b6a1 | 1.2.0, 9686fbaea864aa19f0675e486672b6a77811b6a1 |
Published upstream
Oct 2, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 2, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 2, 2026
Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video.
Quoted source text, attributed separately from HOL analysis.