P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Discord's encrypted-call flaw needed signalling control. The fix shipped five weeks before disclosure

CVE-2026-104480 describes an MLS Welcome roster check missing from older libdave builds. An attacker would need control of the DAVE signalling path; the public record does not establish widespread call compromise.

By Parminder Kumar Sharma · · 4 min read

Encryption depends on knowing who is in the group

Discord's libdave library is part of its end-to-end encrypted media system. CVE-2026-104480, published on 2 October, says versions before 1.2.0 did not reject an MLS Welcome message if the resulting group roster contained a participant the client did not recognise. An attacker able to change signalling messages could cause an affected client to accept an unauthorised member into an audio or video session.

This is a membership-validation problem. It does not mean the media encryption itself was mathematically broken. If the wrong person is admitted as a group member, sound encryption can faithfully protect media for the wrong set of people. That distinction is the useful lesson of this disclosure.

The trust decision described by the CVE record.

StepRequired conditionPotential result
SignallingAttacker controls the DAVE signalling path, such as the voice gateway or an equivalent positionWelcome message can be added, altered or withheld
Roster validationAffected libdave build before 1.2.0 accepts an unrecognised participantClient accepts the wrong membership
MediaUnauthorised member is in the encrypted sessionAudio/video confidentiality and integrity can be affected

Where the Voice Gateway sits in the trust decision

DAVE signalling diagram: an attacker who controls signalling can present an MLS Welcome containing an unrecognised member; libdave before 1.2.0 accepted the roster; version 1.2.0 rejects it. No exploited call is documented.
A correct encryption scheme still depends on rejecting a group roster that contains an unrecognised member.

DAVE uses Message Layer Security (MLS) to manage who belongs to an encrypted audio or video group. Discord's Voice Gateway carries the signalling that clients use to set up and update that group, while the SFU forwards encrypted media frames. A Welcome message lets a participant join an MLS group. Before accepting it, a client needs to match the resulting cryptographic membership to the participants it expects.

The CVE says libdave before 1.2.0 failed that last check when a Welcome led to an unrecognised group member. The attacker condition is substantial: control of the DAVE signalling path, such as the voice gateway or equivalent ability to alter, add or withhold messages. It is not enough simply to join a normal call. If the condition and vulnerable code coincide, the wrong member can become part of the encrypted group and gain access to media intended for that group. The CVE describes a possible confidentiality and integrity impact, not a confirmed recording of calls.

The mechanism crosses a membership boundary, not the media cipher.

LayerNormal roleFailure or fix
Voice Gateway signallingDelivers MLS messagesAttacker-controlled signalling is the prerequisite
MLS Welcome validationChecks membership against expected participantsPre-1.2.0 missed unrecognised member; 1.2.0 rejects
Encrypted mediaProtects frames for accepted groupWrong accepted member can defeat intended audience

What call participants can independently check

DAVE documents a Voice Privacy Code that group members may compare through an independent channel. This can help participants assess whether they share the same encrypted conversation, but the public CVE does not show that checking the code would always detect or prevent this particular roster bug. The engineering fix is to ship libdave 1.2.0 or later and validate every membership transition. Incident claims still need evidence that an attacker controlled signalling and that affected clients were in the call.

The patch preceded the CVE by more than a month

The corrective commit restores stricter validation of the Welcome state. The libdave v1.2.0 release is dated 26 August 2026. The CVE record appeared 2 October 2026, roughly five weeks later. The elapsed time between fix and disclosure is visible; whether vulnerable clients remained in use during that period is not.

The record does not say an attacker exploited this flaw, identify affected calls, or state which current Discord clients had an older library. A headline claiming all Discord calls were exposed would go beyond the evidence. Third-party applications embedding libdave should check their actual bundled version, not only the upstream release date.

What implementers should take from it

Take this with you

For teams using libdave

  • Confirm whether your application uses libdave and which version is actually shipped to clients.
  • Update builds older than 1.2.0 and verify that the deployed package includes the roster-validation change.
  • Test membership changes as a security property: a Welcome message must not admit a participant outside the expected roster.
  • Do not report a media-content breach without independent evidence of signalling-path control and affected sessions.

Sources

  1. PrimaryCVE-2026-104480 recordCVE Programaccessed 2026-10-02
  2. PrimaryRestore MLS Welcome validationDiscord GitHubaccessed 2026-10-02
  3. Primarylibdave v1.2.0 releaseDiscord GitHubaccessed 2026-10-02
  4. PrimaryDAVE protocol documentationDAVE Protocolaccessed 2026-10-02
  5. PrimaryIntroducing DAVE end-to-end encryption for audio and videoDiscordaccessed 2026-10-02

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.