CVE-2025-57156

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/01/2026
Last modified:
20/01/2026

Description

NULL pointer dereference in the dacp_reply_playqueueedit_clear function in src/httpd_dacp.c in owntone-server through commit 6d604a1 (newer commit after version 28.12) allows remote attackers to cause a Denial of Service (crash).

Impact