OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100848

HIGH · CVSS 7.1 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

AzuraCast versions prior to 0.23.8 are vulnerable due to inadequate validation of "Remote Relay" URLs, allowing users with limited permissions to configure URLs that point to internal or private network addresses. This flaw can lead to server-side request forgery (SSRF), enabling attackers to exploit internal resources through unauthorized HTTP requests. Organizations using AzuraCast should prioritize remediation to mitigate potential exposure to sensitive internal systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100848
Severity
HIGH
CVSS
7.1
EPSS
0.18%

Original NVD Description

AzuraCast (Composer package azuracast/azuracast) before 0.23.8 validates a station's "Remote Relay" URL only for URL syntax and an http/https scheme (Utilities\Urls::parseUserUrl, used by StationRemote::getUrlAsUri) and performs no host or IP address restriction. A user holding only the station-scoped RemoteRelays permission can therefore set a Remote Relay URL pointing at loopback, private-network, or cloud-metadata addresses (e.g. http://127.0.0.1:<port>/ or http://169.254.169.254/latest/meta-data/), and AzuraCast's periodic background Now Playing sync (AbstractRemote::getNowPlayingAsync) will automatically and repeatedly issue HTTP requests to that address, resulting in server-side request forgery against internal resources. This affects the main branch as of commit bcf8754eef3a268ad82c3db4d81f7920c3c28b56 (2026-07-31); no patched version is available at the time of the advisory.