PT-2026-99469 · Azuracast · Azuracast

CVE-2026-100849

·

Published

2026-09-27

·

Updated

2026-09-28

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions AzuraCast versions prior to 0.23.8
Description Insufficient URL validation in the getValidUrl() function within the AbstractConnector.php file allows for server-side request forgery. The validation process only rejects literal link-local IP addresses, failing to block loopback addresses, RFC1918 private ranges, or non-literal-IP hostnames. A user with station-scoped WebHooks permissions can configure a webhook targeting internal or private networks, causing the server to send an outbound HTTP POST request containing Now Playing data. This can be triggered on demand via the PUT /station/{id}/webhook/{id}/test endpoint.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100849
GHSA-3JP3-3WQW-JVW4

Affected Products

Azuracast