mediumVulnerability

GHSA-g588-cjg3-6g78

Processing the raw `ValidateAuthTicketResponse_t` callback data panics when the `m_eAuthSessionResponse` field is `k_EAuthSessionResponseAuthTicketNetworkIdentityFailure`. This can lead to denial of service in game clients and servers using the `begin_authentication_session` API to authenticate players if a malicious game client sends an authentication ticket with a network identity that does not match that of the verifier.

Properties

ghsa_id
GHSA-g588-cjg3-6g78
severity
medium
summary
Steamworks game clients/servers using P2P authentication vulnerable to denial of service
cve_id
GHSA-g588-cjg3-6g78
is_ghsa_only
true
ghsa_published
2026-05-11T14:40:17Z
source_url
https://github.com/advisories/GHSA-g588-cjg3-6g78
ghsa_updated
2026-05-11T14:40:17Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]rust/steamworks

AFFECTS (1)

[Software]rust/steamworks

HAS_WEAKNESS (1)

[Weakness]Improper Input Validation

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-g588-cjg3-6g78 — Ninja Signal Threat Intelligence | Ninja Signal