216.73.217.174

CVE-2026-41458

· Published 22/04/2026 03:16 · Modified 22/04/2026 21:21

Labels: CVE-2026-41458 2026-04-22CVE-2026-41458CWE-362[email protected]

Essential information

Published
22/04/2026 03:16
Modified
22/04/2026 21:21
Author
Creator
CVSS
8.2 HIGH (v3) 8.2 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP session list. Attackers can flood the DAAP /login endpoint with concurrent requests to trigger a remote denial of service condition without requiring authentication.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
owntone / server cpe:2.3:a:owntone:server:28.4-29.0:*:*:*:*:*:*:*

References