Server-Side Request Forgery in AzuraCast Remote Relay URL
CVE-2026-100848
7.1HIGH
What is CVE-2026-100848?
AzuraCast prior to version 0.23.8 contains a vulnerability that allows users with specific permissions to set a Remote Relay URL without proper validation of the host or IP address. This flaw enables the user to direct requests to internal resources and metadata services, potentially exposing sensitive information or compromising the integrity of the server. The issue arises from insufficient checks on supplied URLs, where only the syntax and scheme are validated, leading to potential exploitation during the Now Playing sync process. It's essential for users of AzuraCast to remain informed of this vulnerability and monitor for future patches.
Affected Version(s)
AzuraCast 0 < 0.23.8
AzuraCast 0.23.8
