Server-Side Request Forgery in AzuraCast Remote Relay URL
CVE-2026-100848

7.1HIGH

Key Information:

Vendor

Azuracast

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-100848?

AzuraCast prior to version 0.23.8 contains a vulnerability that allows users with specific permissions to set a Remote Relay URL without proper validation of the host or IP address. This flaw enables the user to direct requests to internal resources and metadata services, potentially exposing sensitive information or compromising the integrity of the server. The issue arises from insufficient checks on supplied URLs, where only the syntax and scheme are validated, leading to potential exploitation during the Now Playing sync process. It's essential for users of AzuraCast to remain informed of this vulnerability and monitor for future patches.

Affected Version(s)

AzuraCast 0 < 0.23.8

AzuraCast 0.23.8

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

senti-man
.