CVE-2026-26828
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
23/03/2026
Last modified:
23/03/2026
Description
A NULL pointer dereference in the daap_reply_playlists function (src/httpd_daap.c) of owntone-server commit 3d1652d allows attackers to cause a Denial of Service (DoS) via sending a crafted DAAP request to the server
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



