phanan/koel
Packagist7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting phanan/koelpage 1 of 1
- CVE-2021-33563HIGHCVSS 7.5EG 7.5✓ Fixed in 5.1.42021-05-24
vulnerable: 1.0.0-beta ... v5.1.3 (47 versions)
Koel before 5.1.4 lacks login throttling, lacks a password strength policy, and shows whether a failed login attempt had a valid username. This might make brute-force attacks easier.
- CVE-2026-47260HIGHCVSS 7.7EG 7.7✓ Fixed in 9.3.52026-05-29
vulnerable: 1.0.0-beta ... v9.3.4 (162 versions)
Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the podcast feed URL via the SafeUrl rule (DNS resolution + public IP check), but the individual episode <enclosure url="..."> values extracted fr…
- CVE-2026-50552MEDIUMCVSS 6.3EG 6.3✓ Fixed in 9.7.12026-06-12
vulnerable: 1.0.0-beta ... v9.7.0 (170 versions)
Koel is a free, open-source music streaming solution. Prior to version 9.7.1, Koel contains a Server-Side Request Forgery (SSRF) vulnerability in the radio station creation endpoint (POST /api/radio/stations). The url field validation rule…
- CVE-2026-54491HIGHCVSS 7.1EG 7.1✓ Fixed in 9.7.12026-07-15
vulnerable: 1.0.0-beta ... v9.7.0 (170 versions)
Koel is a free, open-source music streaming solution. Prior to 9.7.1, outbound podcast and radio fetch paths perform a point-in-time App\Helpers\Network::isPublicHost() or isSafeUrl() check without pinning the validated address, and most p…
- CVE-2026-54492MEDIUMCVSS 4.3EG 4.3✓ Fixed in 9.7.02026-07-15
vulnerable: 1.0.0-beta ... v9.6.0 (169 versions)
Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createPodcastChannel.view route accepts an authenticated user's private URL because app/Http/Requests/Subsonic/CreatePodcastChannelRequest.php do…
- CVE-2026-54493HIGHCVSS 7.7EG 7.7✓ Fixed in 9.7.02026-07-15
vulnerable: 1.0.0-beta ... v9.6.0 (169 versions)
Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createInternetRadioStation.view and updateInternetRadioStation.view routes accept an authenticated user's streamUrl without the SafeUrl and HasAu…
- CVE-2026-54494MEDIUMCVSS 5.3EG 5.3✓ Fixed in 9.7.12026-07-15
vulnerable: 1.0.0-beta ... v9.7.0 (170 versions)
Koel is a free, open-source music streaming solution. Prior to 9.7.1, App\Helpers\Network::isPublicHost() uses filter_var() with FILTER_FLAG_NO_PRIV_RANGE and FILTER_FLAG_NO_RES_RANGE, which treats NAT64 64:ff9b::/96 and 6to4 2002::/16 wra…
Check whether phanan/koel is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for phanan/koel CVEs against the assets you own.
Start Free Scan →