CVE Database
/

CVE-2026-41458

Back to search

CVE-2026-41458

Published: Apr 22, 2026

Modified: May 25, 2026

PUBLISHED

Description

OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP session list. Attackers can flood the DAAP /login endpoint with concurrent requests to trigger a remote denial of service condition without requiring authentication.

VendorProductVersions

owntone

owntone-server

affected
28.4.0 - < 29.1.0
unaffected
dca94641a5ed66500822dd51281774794cdb6c22

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now