Known Vulnerabilities for Clash by Clash Project
Listed below are 4 of the newest known vulnerabilities associated with "Clash" by "Clash Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-43114 json | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-matchin... | Not Provided | 2026-05-06 | 2026-07-15 |
| CVE-2026-26422 json | clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation. | Not Provided | 2026-06-06 | 2026-06-08 |
| CVE-2023-24205 json | Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overw... | 9.8 - CRITICAL | 2023-02-23 | 2023-03-03 |
| CVE-2022-40126 json | A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privileges... | 7.8 - HIGH | 2022-09-29 | 2022-10-04 |
| CVE-2022-26255 json | Clash for Windows v0.19.8 was discovered to allow arbitrary code execution via a crafted payload injected into the Proxies na... | 9.8 - CRITICAL | 2022-03-28 | 2023-08-08 |
| CVE-2020-24772 json | In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that would... | 8.8 - HIGH | 2022-03-21 | 2022-03-29 |