No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 22 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Owntone
Owntone server |
|
| Vendors & Products |
Owntone
Owntone server |
Wed, 22 Apr 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP session list. Attackers can flood the DAAP /login endpoint with concurrent requests to trigger a remote denial of service condition without requiring authentication. | |
| Title | OwnTone Server < 29.1 Race Condition DoS via DAAP Login | |
| Weaknesses | CWE-362 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-22T18:06:24.028Z
Reserved: 2026-04-20T16:07:47.310Z
Link: CVE-2026-41458
Updated: 2026-04-22T18:06:13.339Z
Status : Deferred
Published: 2026-04-22T03:16:01.067
Modified: 2026-04-22T21:21:26.840
Link: CVE-2026-41458
No data.
OpenCVE Enrichment
Updated: 2026-04-22T11:44:51Z