AzuraCast

11 known vulnerabilities in AzuraCast, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-100857 CVSS 8.6 high AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize…
  • CVE-2026-100856 CVSS 8.7 high AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete migration from the…
  • CVE-2026-100855 CVSS 7.1 high AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}/play endpoint…
  • CVE-2026-100854 CVSS 5.3 medium AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the Liquidsoap API endpoint and incorrectly derives the AutoDJ flag…
  • CVE-2026-100853 CVSS 8.2 high In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allowing…
  • CVE-2026-100852 CVSS 8.7 high AzuraCast before 0.23.8 contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to…
  • CVE-2026-100851 CVSS 7.2 high AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows…
  • CVE-2026-100850 CVSS 4.8 medium AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote playlist fetch…
  • CVE-2026-100849 CVSS 7.1 high AzuraCast is a self-hosted web radio management suite. In AzuraCast before 0.23.8, the station webhook URL validation in…
  • CVE-2026-100848 CVSS 7.1 high AzuraCast (Composer package azuracast/azuracast) before 0.23.8 validates a station's "Remote Relay" URL only for URL syntax and an…
  • CVE-2026-100847 CVSS 8.7 high AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php…