Critical severity9.1NVD Advisory· Published Sep 25, 2023· Updated Jun 17, 2026
CVE-2023-43644
CVE-2023-43644
Description
Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafted requests are sent to sing-box. This affects all SOCKS5 inbounds with user authentication and an attacker may be able to bypass authentication. Users are advised to update to sing-box 1.4.4 or to 1.5.0-rc.4. Users unable to update should not expose the SOCKS5 inbound to insecure environments.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/sagernet/sing-boxGo | < 1.4.5 | 1.4.5 |
github.com/sagernet/sing-boxGo | >= 1.5.0-beta.1, < 1.5.0-rc.5 | 1.5.0-rc.5 |
github.com/sagernet/singGo | < 0.2.12-0.20230925092853-5b05b5c147d9 | 0.2.12-0.20230925092853-5b05b5c147d9 |
Affected products
3- ghsa-coords2 versions
< 0.2.12-0.20230925092853-5b05b5c147d9+ 1 more
- (no CPE)range: < 0.2.12-0.20230925092853-5b05b5c147d9
- (no CPE)range: < 1.4.5
Patches
Vulnerability mechanics
References
6- github.com/SagerNet/sing-box/security/advisories/GHSA-r5hm-mp3j-285gnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-r5hm-mp3j-285gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-43644ghsaADVISORY
- github.com/SagerNet/sing-box/commit/9891fd672f5da9f20f59a1693271a946727f49e2ghsaWEB
- github.com/SagerNet/sing-box/releases/tag/v1.4.5ghsaWEB
- github.com/SagerNet/sing/commit/5b05b5c147d9650e8accb4441e216c72a61f4859ghsaWEB
News mentions
0No linked articles in our index yet.