OwnTone Server versions 28.4 through 29.0 are affected by a race condition vulnerability (CVE-2026-41458) in the DAAP login handler that permits unauthenticated remote denial of service attacks. The vulnerability stems from unsynchronized access to the global DAAP session list, allowing attackers to manipulate concurrent requests without authentication credentials. The attack is straightforward to execute, requiring only flooding of the DAAP /login endpoint with concurrent requests to crash the server. The CVSS score is not yet published, but the EPSS score of 0.00312 indicates low exploit probability relative to other CVEs, and the vulnerability has not been added to the Known Exploited Vulnerabilities catalog. There is currently no evidence of active exploitation, and community attention remains limited, with the FAUCET Risk Score of 50.0/100 reflecting moderate but not critical concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 28.4.0, < 29.1.0CPE match | cpe:2.3:a:owntone:owntone_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.