关键漏洞信息 漏洞类型: Denial of Service and disk exhaustion via oversized parameter in and endpoints 严重性: Critical (9.2/10) CVE ID: CVE-2026-25579 受影响版本: < 0.60.0 修复版本: 0.60.0 描述摘要 攻击向量: Network 攻击复杂度: Low 系统影响: - 可用性: High (可导致服务完全中断) - 完整性, 保密性: None 漏洞细节 问题: Authenticated users can crash the Navidrome server by supplying an excessively large size parameter in certain endpoints. 具体表现: - Inefficient handling of parameter leading to excessive memory allocation and potential OOM killer termination. - If memory is sufficient, oversized images are written to cache, rapidly exhausting disk space. 影响 DoS: Service outage due to memory exhaustion or disk space exhaustion. 主机影响: Potential destabilization or crash of the host system in certain configurations. 修复建议 Upgrade to version 0.60.0 or above where the issue is patched.