CVE-2026-25579
MEDIUM WAF: MediumNavidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, authenticated users can crash the Navidrome server by supplying an excessively large size parameter to /rest/getCoverArt or to a shared-image URL (/share/img/
WAF Coverage Analysis
OWASP: A05:2021 Security Misconfiguration
Affected Software
| Vendor | Product | Version |
|---|---|---|
| navidrome | navidrome | up to 0.60.0 |
References
- github.com (Product, Release Notes)
- github.com (Exploit, Vendor Advisory)