Denial of Service Vulnerability in Owntone Server by Owntone
CVE-2025-57155

7.5HIGH

Key Information:

Vendor

Owntone

Vendor
CVE Published:
20 January 2026

What is CVE-2025-57155?

The vulnerability involves a NULL pointer dereference within the daap_reply_groups function located in src/httpd_daap.c of Owntone Server. This flaw, introduced in versions beyond 28.2 through the commit with hash 5e6f19a, allows remote attackers to exploit the server, leading to a Denial of Service condition. Upgrading to patched versions is crucial to mitigate potential attacks.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.