CVE-2026-100849: AzuraCast before 0.23.8 SSRF Filter Bypass via Hostname and Private IPs
AzuraCast is a self-hosted web radio management suite. In AzuraCast before 0.23.8, the station webhook URL validation in AbstractConnector::getValidUrl() (backend/src/Webhook/Connector/AbstractConnector.php), used by the Generic and Discord webhook connectors, rejects only URLs whose host is a literal link-local IP address (169.254.0.0/16 or fe80::/10). Loopback addresses and RFC1918 private ranges are not rejected, and any non-literal-IP hostname causes the IP parsing call to throw, which skips the check entirely. A user holding only the station-scoped WebHooks permission can therefore configure a webhook pointing at an internal, loopback, or private-network target and cause the server to issue an outbound HTTP POST containing the station's Now Playing data, resulting in server-side request forgery. The PUT /station/{id}/webhook/{id}/test endpoint allows the same low-privileged user to trigger the request on demand. At the time of the advisory no patched version was available.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AzuraCastto a version that resolves this vulnerability.Fixed in 0.23.8
Event History
Frequently Asked Questions
Who can exploit this issue?
A user with only the station-scoped WebHooks permission can configure and trigger a malicious webhook. No broader administrative permission is described as necessary.
Which webhook configurations are affected?
The affected validation is used by the Generic and Discord webhook connectors. It permits loopback and RFC1918 private addresses, and hostname-based URLs bypass the IP validation because non-literal hostnames skip the check.
Can the request be triggered on demand?
Yes. A user with the relevant station WebHooks permission can use the PUT /station/{id}/webhook/{id}/test endpoint to cause the outbound HTTP POST on demand.
What data is sent to the target?
The server sends an outbound HTTP POST containing the station's Now Playing data to the configured target.
Is a patched release available?
At the time of the advisory, no patched version was available.