Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100848— AzuraCast before 0.23.8 Server-Side Request Forgery via Remote Relay URL

Quick assessment

Affected
AzuraCast AzuraCast
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

AzuraCast(Composer 包 azuracast/azuracast)在 0.23.8 版本之前,仅对电台的“远程中继”(Remote Relay)URL 进行语法校验以及检查其是否使用 http/https 协议(通过 Utilities\Urls::parseUserUrl 函数实现,该函数被 StationRemote::getUrlAsUri 调用),但未对主机名或 IP 地址施加任何限制。因此,即使攻击者仅拥有受限在电台范围内的 RemoteRelays 权限,也可以将远程中继 URL 设置为

CVSS 7.1 · High EPSS 0.18% · P7

Possible ATT&CK Techniques 1 AI

T1598.001 · Spearphishing Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100848

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
AzuraCast before 0.23.8 Server-Side Request Forgery via Remote Relay URL
Source: CVE Program / CVE List V5
Vulnerability Description
AzuraCast (Composer package azuracast/azuracast) before 0.23.8 validates a station's "Remote Relay" URL only for URL syntax and an http/https scheme (Utilities\Urls::parseUserUrl, used by StationRemote::getUrlAsUri) and performs no host or IP address restriction. A user holding only the station-scoped RemoteRelays permission can therefore set a Remote Relay URL pointing at loopback, private-network, or cloud-metadata addresses (e.g. http://127.0.0.1:<port>/ or http://169.254.169.254/latest/meta-data/), and AzuraCast's periodic background Now Playing sync (AbstractRemote::getNowPlayingAsync) will automatically and repeatedly issue HTTP requests to that address, resulting in server-side request forgery against internal resources. This affects the main branch as of commit bcf8754eef3a268ad82c3db4d81f7920c3c28b56 (2026-07-31); no patched version is available at the time of the advisory.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
AzuraCast AzuraCast 0 ~ 0.23.8 -

II. Public POCs for CVE-2026-100848

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100848

请登录查看更多情报信息。

News Coverage for CVE-2026-100848 (1)

Other References for CVE-2026-100848 (1)

Same Patch Batch · AzuraCast · 2026-09-27 · 11 CVEs total

CVE-2026-100852 8.8 HIGH AzuraCast before 0.23.8 Command Injection via Streamer Username
CVE-2026-100856 8.8 HIGH AzuraCast before 0.23.6 Code Injection via Remote Relay Password
CVE-2026-100857 8.0 HIGH AzuraCast before 0.23.4 Remote Code Execution via Liquidsoap string interpolation
CVE-2026-100850 7.7 HIGH AzuraCast before 0.23.8 SSRF and Local File Read via Remote Playlist
CVE-2026-100851 7.6 HIGH AzuraCast before 0.23.8 Broken Access Control via GET /api/station/{id}/vue/profile
CVE-2026-100847 7.5 HIGH AzuraCast before 0.23.8 DQL Injection via sortOrder
CVE-2026-100849 7.1 HIGH AzuraCast before 0.23.8 SSRF Filter Bypass via Hostname and Private IPs
CVE-2026-100855 6.5 MEDIUM AzuraCast before 0.23.6 Missing Permission Check via /play
CVE-2026-100854 6.3 MEDIUM AzuraCast before 0.23.6 Metadata Injection via Liquidsoap API
CVE-2026-100853 5.9 MEDIUM AzuraCast before 0.23.8 On-Demand Download Endpoint Authorization Bypass

IV. Related Vulnerabilities

V. Comments for CVE-2026-100848

No comments yet


Leave a comment