Executive brief
Navidrome allows an authentication bypass in Subsonic API with non-existent username in github.com/navidrome/navidrome
Affected products
- Go github.com/navidrome/navidrome
Junglewise Threat Intelligence
CVE-2025-27112 · Severity: medium · CVSS 4 · Published 2025-03-03
Technologies: github.com/navidrome/navidrome (Go). Vendors: Go.
Navidrome allows an authentication bypass in Subsonic API with non-existent username in github.com/navidrome/navidrome