azuracast/azuracast
Packagist9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting azuracast/azuracastpage 1 of 1
- CVE-2023-2191MEDIUMCVSS 4.8EG 4.8fixed in 0.18.02023-04-20
vulnerable: 0.10.0 ... 0.9.9 (53 versions)
Cross-site Scripting (XSS) - Stored in GitHub repository azuracast/azuracast prior to 0.18.
- CVE-2023-2531CRITICALCVSS 9.8EG 9.8fixed in 0.18.32023-05-05
vulnerable: 0.10.0 ... 0.9.9 (56 versions)
Improper Restriction of Excessive Authentication Attempts in GitHub repository azuracast/azuracast prior to 0.18.3.
- CVE-2025-67737LOWCVSS 3.7EG 3.7fixed in 0.23.22025-12-12
vulnerable: 0.10.0 ... 0.9.9 (76 versions)
AzuraCast is a self-hosted, all-in-one web radio management suite. Versions 0.23.1 mistakenly include an API endpoint that is intended for internal use by the SFTP software sftpgo, exposing it to the public-facing HTTP API for AzuraCast in…
- CVE-2026-100854MEDIUMCVSS 6.3EG 6.3fixed in 0.23.62026-09-27
vulnerable: 0.10.0 ... 0.9.9 (80 versions)
AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the Liquidsoap API endpoint and incorrectly derives the AutoDJ flag from header presence rather than validated value. Users with View station permission can inject arbit…
- CVE-2026-100855MEDIUMCVSS 6.5EG 6.5fixed in 0.23.62026-09-27
vulnerable: 0.10.0 ... 0.9.9 (80 versions)
AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}/play endpoint that allows authenticated users to download media files from any station. Attackers can enumerate media …
- CVE-2026-100856HIGHCVSS 8.8EG 8.8fixed in 0.23.62026-09-27
vulnerable: 0.10.0 ... 0.9.9 (80 versions)
AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete migration from the vulnerable cleanUpString method to toRawString. Attackers with RemoteRelays station permission can inje…
- CVE-2026-100857HIGHCVSS 8.0EG 8.0fixed in 0.23.42026-09-27
vulnerable: 0.10.0 ... 0.9.9 (78 versions)
AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to…
- CVE-2026-42605HIGHCVSS 8.8EG 8.8fixed in 0.23.62026-05-09
vulnerable: 0.10.0 ... 0.9.9 (80 versions)
AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js media upload endpoint (POST /api/station/{station_id}/files/upload) is not sanitized for path…
- CVE-2026-42606HIGHCVSS 8.8EG 8.8fixed in 0.23.62026-05-09
vulnerable: 0.10.0 ... 0.9.9 (80 versions)
AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middleware unconditionally trusts the client-supplied X-Forwarded-Host HTTP header with no trusted proxy allowlist. An unauthen…
Check whether azuracast/azuracast is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for azuracast/azuracast CVEs against the assets you own.
Book a Demo →