Owncast Project maintains a self-hosted live-streaming platform that, despite a narrow product focus, sits at the boundary between user content and network connectivity, creating a meaningful attack surface for server-side and web-layer flaws. Its vulnerability footprint skews strongly toward critical-severity outcomes and frequently acquires public exploit code; the recurring weakness classes—server-side request forgery, cross-site request forgery, code injection, path traversal, and cross-site scripting—reflect the challenges of safely handling untrusted input, user-generated content, and network requests in a streaming application. Defenders deploying Owncast should prioritize patching for these input-handling and injection-class vulnerabilities; current severity, exploitation, and exposure data are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Owncast Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-3188MEDIUM Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0. | Jun 10, 2023 | 6.5 | 32 | NO | YES |
CVE-2022-3751CRITICAL SQL Injection in GitHub repository owncast/owncast prior to 0.0.13. | Nov 29, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-46480CRITICAL An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the indieauth function. | Nov 27, 2023 | 9.8 | 27 | NO | NO |
CVE-2024-29026CRITICAL Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1.2 and prior, a lenient CORS policy allows attackers to make | Mar 20, 2024 | 9.1 | 26 | NO | NO |
CVE-2021-39183MEDIUM Owncast is an open source, self-hosted live video streaming and chat server. In affected versions inline scripts are executed when Javascript is parsed via a paste action. This iss | Dec 14, 2021 | 6.1 | 21 | NO | NO |
CVE-2024-31450MEDIUM Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. The Owncast application exposes an administrator API at the URL /api/admin. | Apr 19, 2024 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Owncast Project.
Media articles that mention a CVE ID that affects a product developed by Owncast Project — matched by CVE ID, not by vendor name.