Koel is a personal music-streaming and management application with a narrow, focused product scope, presenting a self-hosted or small-deployment attack surface. Its observed vulnerability profile centers on password-hashing implementation, where the application employs cryptographic schemes with insufficient computational effort, a foundational weakness in credential storage that warrants attention during deployment and updates. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Koel over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33563HIGH Koel before 5.1.4 lacks login throttling, lacks a password strength policy, and shows whether a failed login attempt had a valid username. This might make brute-force attacks easie | May 24, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Koel.
Media articles that mention a CVE ID that affects a product developed by Koel — matched by CVE ID, not by vendor name.