CVE-2026-31804 describes an unauthenticated server-side request forgery (SSRF) vulnerability in Tautulli versions prior to 2.17.0. This flaw allows an attacker to leverage the /pms_image_proxy endpoint to force the associated Plex Media Server to make outbound HTTP requests to arbitrary URLs, potentially accessing internal network resources. Rated Medium severity with a CVSS score of 4.0, the attack requires high complexity but does not need authentication, primarily impacting confidentiality by enabling network reconnaissance. There is no evidence of active exploitation, nor is public exploit code available, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.17.0CPE matchmatch criteria | cpe:2.3:a:tautulli:tautulli:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.