Denial of Service Vulnerability in Jellyfin Media Server
CVE-2026-35034
6.5MEDIUM
What is CVE-2026-35034?
Jellyfin, an open-source self-hosted media server, has a vulnerability in its SyncPlay group creation endpoint (POST /SyncPlay/New). This issue allows authenticated users to create groups with names of unlimited size, due to insufficient input validation. By exploiting this vulnerability, attackers can submit large payloads along with arbitrary group IDs. This can significantly increase memory usage and potentially lead to a denial of service, affecting other clients trying to join SyncPlay groups. This issue has been addressed in version 10.11.7.
Affected Version(s)
jellyfin < 10.11.7
