GHSA-c3p4-vm8f-386p · Severity: medium · Ecosystem: go — Navidrome allows an authentication bypass in Subsonic API with non-existent username
Navidrome is an open source web-based music collection server and streamer. Starting in version 0.52.0 and prior to version 0.54.5, in certain Subsonic API endpoints, a flaw in the authentication check process allows an attacker to specify any arbitrary username that does not exist on the system, along with a salted hash of an empty password. Under these conditions, Navidrome treats the request as authenticated, granting access to various Subsonic endpoints without requiring valid credentials. An attacker can use any non-existent username to bypass the authentication system and gain access to various read-only data in Navidrome, such as user playlists. However, any attempt to modify data fails with a "permission denied" error due to insufficient permissions, limiting the impact to unauthorized viewing of information. Version 0.54.5 contains a patch for this issue.
Conclusion & alert: CVE-2025-27112 is rated High Exploit Risk (71.4/100): CVSS Medium severity, with high exploitation likelihood (EPSS 28.46%, 97th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-12 | 33.58% | 28.46% | -5.12% |
| 2 | 2026-04-05 | 32.62% | 33.58% | +0.96% |
| 3 | 2026-04-04 | — | 32.62% | — |
Full EPSS history (28 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.9 | 4.0 | MEDIUM |
|
— | — | [email protected] |
| 6.5 | 3.1 | MEDIUM |
|
3.9 | 2.5 | [email protected] |
GHSA-c3p4-vm8f-386p · Severity: medium · Ecosystem: go — Navidrome allows an authentication bypass in Subsonic API with non-existent username
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
medium | CVE-2025-27112: 1 source package rows (navidrome); 6 state rows across 2 repos (3.22-community, edge-community); fixed 0, open 6. | https://security.alpinelinux.org/vuln/CVE-2025-27112 |