Server-Side Request Forgery and Local File Read in AzuraCast by AzuraCast
CVE-2026-100850

4.8MEDIUM

Key Information:

Vendor

Azuracast

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-100850?

AzuraCast versions prior to 0.23.8 are impacted by a vulnerability that allows for server-side request forgery (SSRF) and local file reading. By utilizing the AutoDJ remote playlist feature, users with Media permissions can create or update playlists that include a remote URL pointing to a file or internal HTTP endpoint. This malicious action leads to the backend's direct use of user-supplied URLs without validating the scheme, exposing sensitive files within the web container, such as /etc/passwd, and internal HTTP request bodies. The vulnerability exists due to improper handling of URLs in the AutoDJ module, posing a significant risk of unauthorized file disclosure.

Affected Version(s)

AzuraCast 0 < 0.23.8

AzuraCast 0.23.8

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alpastx
.