CVE-2026-100848: AzuraCast before 0.23.8 Server-Side Request Forgery via Remote Relay URL
AzuraCast (Composer package azuracast/azuracast) before 0.23.8 validates a station's "Remote Relay" URL only for URL syntax and an http/https scheme (Utilities\Urls::parseUserUrl, used by StationRemote::getUrlAsUri) and performs no host or IP address restriction. A user holding only the station-scoped RemoteRelays permission can therefore set a Remote Relay URL pointing at loopback, private-network, or cloud-metadata addresses (e.g. http://127.0.0.1:<port>/ or http://169.254.169.254/latest/meta-data/), and AzuraCast's periodic background Now Playing sync (AbstractRemote::getNowPlayingAsync) will automatically and repeatedly issue HTTP requests to that address, resulting in server-side request forgery against internal resources. This affects the main branch as of commit bcf8754eef3a268ad82c3db4d81f7920c3c28b56 (2026-07-31); no patched version is available at the time of the advisory.
Affected Software
Event History
Frequently Asked Questions
What level of access is required to trigger the issue?
A user needs only the station-scoped RemoteRelays permission. Administrative access is not required.
When are requests to the configured destination sent?
AzuraCast's periodic background Now Playing synchronization automatically sends the requests. Requests are repeated as part of that sync process.
What internal targets can be reached through this behavior?
A permitted user can configure HTTP or HTTPS URLs targeting loopback addresses, private-network addresses, or cloud metadata endpoints such as 169.254.169.254.
Is a patched release available?
No patched version was available at the time of the advisory.