AzuraCast is a self-hosted web radio management suite. (CVE-2026-100849)
AzuraCast versions before 0.23.8 contain a server-side request forgery (SSRF) vulnerability in the station webhook URL validation. The validation incorrectly rejects only literal link-local IP addresses but allows loopback and private network addresses, enabling a user with station-scoped WebHooks permission to configure webhooks targeting internal or private network resources. This can cause the server to send HTTP POST requests with station data to unintended internal endpoints. The vulnerability can be triggered on demand via a specific test endpoint. No patch was available at the time of the advisory.
AI Analysis
Technical Summary
AzuraCast before version 0.23.8 has an SSRF vulnerability in AbstractConnector::getValidUrl(), used by Generic and Discord webhook connectors. The URL validation rejects only literal link-local IP addresses (169.254.0.0/16 or fe80::/10) but does not reject loopback or RFC1918 private IP ranges. Non-literal IP hostnames cause the IP parsing to throw an error, skipping validation entirely. Consequently, a user with station-scoped WebHooks permission can configure webhooks pointing to internal, loopback, or private network addresses, causing the server to issue outbound HTTP POST requests with the station's Now Playing data. The PUT /station/{id}/webhook/{id}/test endpoint allows triggering the request manually. No patched version was available at the time of the advisory.
Potential Impact
An attacker with limited station-scoped WebHooks permissions can exploit this vulnerability to make the AzuraCast server send HTTP POST requests to internal or private network addresses. This SSRF can potentially be used to access or interact with internal services not normally reachable externally, leading to information disclosure (high confidentiality impact) and limited integrity impact. Availability is not affected. The vulnerability has a CVSS 3.1 score of 7.1 (high severity).
Mitigation Recommendations
At the time of the advisory, no patch was available. Users should monitor the vendor advisory for updates and apply official fixes once released. Until then, restrict station-scoped WebHooks permissions to trusted users only and avoid configuring webhooks with untrusted URLs. No other vendor-provided mitigations or temporary fixes were indicated.
AzuraCast is a self-hosted web radio management suite. (CVE-2026-100849)
Description
AzuraCast versions before 0.23.8 contain a server-side request forgery (SSRF) vulnerability in the station webhook URL validation. The validation incorrectly rejects only literal link-local IP addresses but allows loopback and private network addresses, enabling a user with station-scoped WebHooks permission to configure webhooks targeting internal or private network resources. This can cause the server to send HTTP POST requests with station data to unintended internal endpoints. The vulnerability can be triggered on demand via a specific test endpoint. No patch was available at the time of the advisory.
CVSS v3.1
Score 7.1high
Affected software
pkg:github/azuracast/AzuraCastRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
AzuraCast before version 0.23.8 has an SSRF vulnerability in AbstractConnector::getValidUrl(), used by Generic and Discord webhook connectors. The URL validation rejects only literal link-local IP addresses (169.254.0.0/16 or fe80::/10) but does not reject loopback or RFC1918 private IP ranges. Non-literal IP hostnames cause the IP parsing to throw an error, skipping validation entirely. Consequently, a user with station-scoped WebHooks permission can configure webhooks pointing to internal, loopback, or private network addresses, causing the server to issue outbound HTTP POST requests with the station's Now Playing data. The PUT /station/{id}/webhook/{id}/test endpoint allows triggering the request manually. No patched version was available at the time of the advisory.
Potential Impact
An attacker with limited station-scoped WebHooks permissions can exploit this vulnerability to make the AzuraCast server send HTTP POST requests to internal or private network addresses. This SSRF can potentially be used to access or interact with internal services not normally reachable externally, leading to information disclosure (high confidentiality impact) and limited integrity impact. Availability is not affected. The vulnerability has a CVSS 3.1 score of 7.1 (high severity).
Mitigation Recommendations
At the time of the advisory, no patch was available. Users should monitor the vendor advisory for updates and apply official fixes once released. Until then, restrict station-scoped WebHooks permissions to trusted users only and avoid configuring webhooks with untrusted URLs. No other vendor-provided mitigations or temporary fixes were indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-c94r-cgjw-f264
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-100849"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6ab89bbff7a7c54106941ebb
Added to database: 09/27/2026, 04:29:51 UTC
Last enriched: 09/27/2026, 04:32:47 UTC
Last updated: 09/27/2026, 13:47:42 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.