Airsonic is a self-hosted music streaming server with a narrow product footprint, where identified vulnerabilities center on input handling and cryptographic implementation in the core Airsonic application. The durable signal reflects XML external entity processing, weak encryption schemes, and improper random-number generation in the authentication and data-handling layers—weaknesses typical of server applications that perform parsing and cryptographic operations without strict input validation and key-derivation controls. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Airsonic Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10908CRITICAL In Airsonic 10.2.1, RecoverController.java generates passwords via org.apache.commons.lang.RandomStringUtils, which uses java.util.Random internally. This PRNG has a 48-bit seed th | Apr 7, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-10907CRITICAL Airsonic 10.2.1 uses Spring's default remember-me mechanism based on MD5, with a fixed key of airsonic in GlobalSecurityConfig.java. An attacker able to capture cookies might be ab | Apr 7, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-20222CRITICAL XXE issue in Airsonic before 10.1.2 during parse. | Apr 4, 2019 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Airsonic Project.
Media articles that mention a CVE ID that affects a product developed by Airsonic Project — matched by CVE ID, not by vendor name.