Critical severity9.1NVD Advisory· Published Sep 25, 2023· Updated Jun 17, 2026
CVE-2023-43644
CVE-2023-43644
Description
Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafted requests are sent to sing-box. This affects all SOCKS5 inbounds with user authentication and an attacker may be able to bypass authentication. Users are advised to update to sing-box 1.4.4 or to 1.5.0-rc.4. Users unable to update should not expose the SOCKS5 inbound to insecure environments.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/sagernet/sing-boxGo | < 1.4.5 | 1.4.5 |
github.com/sagernet/sing-boxGo | >= 1.5.0-beta.1, < 1.5.0-rc.5 | 1.5.0-rc.5 |
github.com/sagernet/singGo | < 0.2.12-0.20230925092853-5b05b5c147d9 | 0.2.12-0.20230925092853-5b05b5c147d9 |
Affected products
19< 1.4.5+ 16 more
- (no CPE)range: < 1.4.5
- cpe:2.3:a:sagernet:sing-box:*:*:*:*:*:*:*:*range: <1.4.5
- cpe:2.3:a:sagernet:sing-box:1.5.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:sagernet:sing-box:1.5.0:beta10:*:*:*:*:*:*
- cpe:2.3:a:sagernet:sing-box:1.5.0:beta11:*:*:*:*:*:*
- cpe:2.3:a:sagernet:sing-box:1.5.0:beta12:*:*:*:*:*:*
- cpe:2.3:a:sagernet:sing-box:1.5.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:sagernet:sing-box:1.5.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:sagernet:sing-box:1.5.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:sagernet:sing-box:1.5.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:sagernet:sing-box:1.5.0:beta6:*:*:*:*:*:*
- cpe:2.3:a:sagernet:sing-box:1.5.0:beta7:*:*:*:*:*:*
- cpe:2.3:a:sagernet:sing-box:1.5.0:beta8:*:*:*:*:*:*
- cpe:2.3:a:sagernet:sing-box:1.5.0:beta9:*:*:*:*:*:*
- cpe:2.3:a:sagernet:sing-box:1.5.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:sagernet:sing-box:1.5.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:sagernet:sing-box:1.5.0:rc3:*:*:*:*:*:*
- ghsa-coords2 versions
< 1.4.5+ 1 more
- (no CPE)range: < 1.4.5
- (no CPE)range: < 0.2.12-0.20230925092853-5b05b5c147d9
Patches
Vulnerability mechanics
References
6- github.com/SagerNet/sing-box/security/advisories/GHSA-r5hm-mp3j-285gnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-r5hm-mp3j-285gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-43644ghsaADVISORY
- github.com/SagerNet/sing-box/commit/9891fd672f5da9f20f59a1693271a946727f49e2ghsaWEB
- github.com/SagerNet/sing-box/releases/tag/v1.4.5ghsaWEB
- github.com/SagerNet/sing/commit/5b05b5c147d9650e8accb4441e216c72a61f4859ghsaWEB
News mentions
0No linked articles in our index yet.