Server-Side Request Forgery Vulnerability in Sonicverse Radio Audio Streaming Stack
CVE-2026-40089

9.9CRITICAL

Key Information:

Vendor
CVE Published:
9 April 2026

What is CVE-2026-40089?

The Sonicverse Radio Audio Streaming Stack is susceptible to a Server-Side Request Forgery (SSRF) due to inadequate validation of user-controlled URLs in its API client. When using the provided installation script, authenticated users can exploit this vulnerability by sending crafted HTTP requests from the dashboard backend to both internal and external systems. This poses a significant risk as it allows unauthorized access to critical server resources, potentially exposing sensitive information.

Affected Version(s)

audiostreaming-stack < cb1ddbacafcb441549fe87d3eeabdb6a085325e4

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.