CVE-2026-41458

OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP session list. Attackers can flood the DAAP /login endpoint with concurrent requests to trigger a remote denial of service condition without requiring authentication.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-04-22 03:16

Updated : 2026-07-14 21:16


NVD link : CVE-2026-41458

Mitre link : CVE-2026-41458

CVE.ORG link : CVE-2026-41458


JSON object : View

Products Affected

No product.

CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')