在 AzuraCast 0.23.6 之前的版本中,Liquidsoap API 端点缺少 RequireInternalConnection 中间件保护,并且错误地根据请求头是否存在来推导 AutoDJ 标志位,而非验证其真实值。拥有“查看电台”权限的用户可以注入任意的当前播放元数据,中断直播广播,并泄露文件系统路径。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100852 | 8.8 HIGH | AzuraCast before 0.23.8 Command Injection via Streamer Username |
| CVE-2026-100856 | 8.8 HIGH | AzuraCast before 0.23.6 Code Injection via Remote Relay Password |
| CVE-2026-100857 | 8.0 HIGH | AzuraCast before 0.23.4 Remote Code Execution via Liquidsoap string interpolation |
| CVE-2026-100850 | 7.7 HIGH | AzuraCast before 0.23.8 SSRF and Local File Read via Remote Playlist |
| CVE-2026-100851 | 7.6 HIGH | AzuraCast before 0.23.8 Broken Access Control via GET /api/station/{id}/vue/profile |
| CVE-2026-100847 | 7.5 HIGH | AzuraCast before 0.23.8 DQL Injection via sortOrder |
| CVE-2026-100849 | 7.1 HIGH | AzuraCast before 0.23.8 SSRF Filter Bypass via Hostname and Private IPs |
| CVE-2026-100848 | 7.1 HIGH | AzuraCast before 0.23.8 Server-Side Request Forgery via Remote Relay URL |
| CVE-2026-100855 | 6.5 MEDIUM | AzuraCast before 0.23.6 Missing Permission Check via /play |
| CVE-2026-100853 | 5.9 MEDIUM | AzuraCast before 0.23.8 On-Demand Download Endpoint Authorization Bypass |
No comments yet