OVERVIEW CVE-2026-35034 affects Jellyfin, an open-source self-hosted media server, in versions prior to 10.11.7. The vulnerability exists in the SyncPlay group creation endpoint where insufficient input validation allows authenticated users to create groups with unlimited name sizes, enabling denial of service attacks against the service. SEVERITY The vulnerability carries a CVSS score of 6.5 (Medium) with a network-based attack vector requiring low complexity and authenticated access. While no confidentiality or integrity impact exists, the availability impact is high—an attacker can exhaust endpoint resources, lock out legitimate clients from joining SyncPlay groups, and trigger out-of-memory conditions leading to process crashes. The attack requires user authentication but no user interaction. EXPLOITATION STATUS The vulnerability is not currently being actively exploited in the wild, with no public exploit code identified and minimal community attention reflected in the inactive status on vulnerability tracking lists. The extremely low EPSS score (0.00044) indicates minimal real-world exploitation probability. Users should prioritize patching to version 10.11.7 or later as a standard hardening measure rather than in response to imminent threats.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.11.7CPE matchmatch criteria | cpe:2.3:a:jellyfin:jellyfin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.