🚨 CVE-2026-100848

CVENOTIFYneutralcyber2026-09-27 02:22:00 UTC
AdYour ad here[email protected]

🚨 CVE-2026-100848 AzuraCast (Composer package azuracast/azuracast) before 0.23.8 validates a station's "Remote Relay" URL only for URL syntax and an http/https scheme (Utilities\Urls::parseUserUrl, used by StationRemote::getUrlAsUri) and performs no host or IP address restriction. A user holding only the station-scoped RemoteRelays permission can therefore set a Remote Relay URL pointing at loopback, private-network, or cloud-metadata addresses (e.g. http://127.0.0.1:<port>/ or…

Read the full story at cvenotify ↗
AdYour ad here[email protected]