Back to search
CVE-2026-41458
Published: Apr 22, 2026
Modified: May 25, 2026
PUBLISHED
Description
OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP session list. Attackers can flood the DAAP /login endpoint with concurrent requests to trigger a remote denial of service condition without requiring authentication.
| Vendor | Product | Versions |
|---|---|---|
owntone | owntone-server | affected 28.4.0 - < 29.1.0unaffected dca94641a5ed66500822dd51281774794cdb6c22 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now