The OwnTone Server versions 28.4 through 29.0 have critical vulnerabilities that allow unauthenticated attackers to crash the server or inject arbitrary SQL expressions.
Claims
The OwnTone Server versions 28.4 through 29.0 have critical vulnerabilities that allow unauthenticated attackers to crash the server or inject arbitrary SQL expressions.
Parent: CybersecurityEntity: OwnTone ServerImpact: negativeDate: Apr 22, 2026Target: The OwnTone Server's security measures and patching process.
Source posts
๐จ EUVD-2026-24585
๐ Score: 6.9/10 (CVSS v3.1)
๐ฆ Product: owntone-server, owntone-server
๐ข Vendor: owntone
๐
Updated: 2026-04-22
๐ OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that allows attackers to inject arbitrary SQL expressions by supplying malicious values through the query= and filter= pa...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24585
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24587
๐ Score: 8.2/10 (CVSS v3.1)
๐ฆ Product: owntone-server, owntone-server
๐ข Vendor: owntone
๐
Updated: 2026-04-22
๐ OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP session list. A...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24587
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability