GHSA-rvqf-8mp6-8qjg · Severity: high — OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP...
OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP session list. Attackers can flood the DAAP /login endpoint with concurrent requests to trigger a remote denial of service condition without requiring authentication.
Conclusion & alert: CVE-2026-41458 is rated Moderate Risk (52.8/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.35%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-03 | 0.65% | 0.35% | -0.30% |
| 2 | 2026-05-24 | 0.60% | 0.65% | +0.05% |
| 3 | 2026-05-17 | — | 0.60% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.2 | 4.0 | HIGH |
|
— | — | [email protected] |
GHSA-rvqf-8mp6-8qjg · Severity: high — OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||