NONE · 0

CVE-2026-41458

OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access...

Vulnerability Description

OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP session list. Attackers can flood the DAAP /login endpoint with concurrent requests to trigger a remote denial of service condition without requiring authentication.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-41458?

CVE-2026-41458 is a documented vulnerability. OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access...

How severe is CVE-2026-41458?

CVSS scoring is not yet available for CVE-2026-41458. Check NVD for updates.

Is there a patch for CVE-2026-41458?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.