Junglewise Threat Intelligence

CVE-2026-100850: AzuraCast AutoDJ server-side request forgery and local file read

CVE-2026-100850 · Severity: high · CVSS 7.7 · Published 2026-09-27

Technologies: AzuraCast. Vendors: AzuraCast.

Executive brief

AzuraCast is a web-based radio streaming management platform. A user with station Media permissions can read sensitive files from the host system or make requests to internal services by setting a remote playlist URL to point at file paths or internal HTTP endpoints. When the AutoDJ feature builds the queue, it fetches this URL without restriction, exposing secrets like configuration files and internal service responses to other users with Broadcasting permissions.

Technical details

The vulnerability is a server-side request forgery (SSRF) and local file read flaw in backend/src/Radio/AutoDJ/QueueBuilder.php:getMediaFromRemoteUrl(). The function passes user-supplied remote_url directly to file_get_contents() with no scheme allowlist and no IP filtering, allowing file:// paths and RFC1918/loopback/metadata endpoints. Playlist entries parsed from the fetched resource are stored in StationQueue.autodj_custom_uri and exposed via the queue API to users with Broadcasting permissions. A patched version exists in 0.23.8.

Affected products

  • AzuraCast AzuraCast before 0.23.8

Timeline

  • 2026-08-08: disclosed: GitHub security advisory GHSA-rrjx-wrhf-8v47 published
  • 2026-09-27: advisory: CVE-2026-100850 published on NVD

References

Related threats