โ† All reports

The OwnTone Server versions 28.4 through 29.0 have critical vulnerabilities that allow unauthenticated attackers to crash the server or inject arbitrary SQL expressions.

CybersecurityTechnologyConflictInformation SecurityApr 22, 2026score 0.172 posts ยท 0 replies across 1 instances
The thread discusses two critical vulnerabilities in the OwnTone Server software, specifically versions 28.4 through 29.0, which include a race condition vulnerability and a SQL injection vulnerability. These vulnerabilities pose significant security risks as they allow unauthenticated attackers to crash the server or inject arbitrary SQL expressions, highlighting the need for urgent patching and security measures.

Claims

The OwnTone Server versions 28.4 through 29.0 have critical vulnerabilities that allow unauthenticated attackers to crash the server or inject arbitrary SQL expressions.
Parent: CybersecurityEntity: OwnTone ServerImpact: negativeDate: Apr 22, 2026Target: The OwnTone Server's security measures and patching process.

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-24585 ๐Ÿ“Š Score: 6.9/10 (CVSS v3.1) ๐Ÿ“ฆ Product: owntone-server, owntone-server ๐Ÿข Vendor: owntone ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that allows attackers to inject arbitrary SQL expressions by supplying malicious values through the query= and filter= pa... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24585 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24587 ๐Ÿ“Š Score: 8.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: owntone-server, owntone-server ๐Ÿข Vendor: owntone ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP session list. A... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24587 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability