CVE-2026-100849: AzuraCast before 0.23.8 SSRF Filter Bypass via Hostname and Private IPs

Published Sep 27, 2026
·
Updated

AzuraCast is a self-hosted web radio management suite. In AzuraCast before 0.23.8, the station webhook URL validation in AbstractConnector::getValidUrl() (backend/src/Webhook/Connector/AbstractConnector.php), used by the Generic and Discord webhook connectors, rejects only URLs whose host is a literal link-local IP address (169.254.0.0/16 or fe80::/10). Loopback addresses and RFC1918 private ranges are not rejected, and any non-literal-IP hostname causes the IP parsing call to throw, which skips the check entirely. A user holding only the station-scoped WebHooks permission can therefore configure a webhook pointing at an internal, loopback, or private-network target and cause the server to issue an outbound HTTP POST containing the station's Now Playing data, resulting in server-side request forgery. The PUT /station/{id}/webhook/{id}/test endpoint allows the same low-privileged user to trigger the request on demand. At the time of the advisory no patched version was available.

Affected Software

1 affected component
azuracast azuracast<0.23.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade AzuraCast to a version that resolves this vulnerability.

    Fixed in 0.23.8

Event History

Sep 27, 2026
CVE Published
via MITRE·01:28 AM
Data Sourced
via MITRE·01:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A user with only the station-scoped WebHooks permission can configure and trigger a malicious webhook. No broader administrative permission is described as necessary.

2

Which webhook configurations are affected?

The affected validation is used by the Generic and Discord webhook connectors. It permits loopback and RFC1918 private addresses, and hostname-based URLs bypass the IP validation because non-literal hostnames skip the check.

3

Can the request be triggered on demand?

Yes. A user with the relevant station WebHooks permission can use the PUT /station/{id}/webhook/{id}/test endpoint to cause the outbound HTTP POST on demand.

4

What data is sent to the target?

The server sends an outbound HTTP POST containing the station's Now Playing data to the configured target.

5

Is a patched release available?

At the time of the advisory, no patched version was available.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203