OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100849

HIGH · CVSS 7.1 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

AzuraCast versions prior to 0.23.8 are vulnerable to server-side request forgery due to inadequate validation of webhook URLs, allowing users with limited permissions to configure webhooks that target internal or private network addresses. This flaw can lead to unauthorized exposure of sensitive data, such as the station's Now Playing information, through outbound HTTP requests. Organizations using AzuraCast should prioritize patching this vulnerability to mitigate potential data leaks and secure their web radio management systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100849
Severity
HIGH
CVSS
7.1
EPSS
0.24%

Original NVD Description

AzuraCast is a self-hosted web radio management suite. In AzuraCast before 0.23.8, the station webhook URL validation in AbstractConnector::getValidUrl() (backend/src/Webhook/Connector/AbstractConnector.php), used by the Generic and Discord webhook connectors, rejects only URLs whose host is a literal link-local IP address (169.254.0.0/16 or fe80::/10). Loopback addresses and RFC1918 private ranges are not rejected, and any non-literal-IP hostname causes the IP parsing call to throw, which skips the check entirely. A user holding only the station-scoped WebHooks permission can therefore configure a webhook pointing at an internal, loopback, or private-network target and cause the server to issue an outbound HTTP POST containing the station's Now Playing data, resulting in server-side request forgery. The PUT /station/{id}/webhook/{id}/test endpoint allows the same low-privileged user to trigger the request on demand. At the time of the advisory no patched version was available.