Executive brief
OwnTone Server, a popular open-source media server, is vulnerable to a flaw that allows unauthenticated users to crash the service. By sending many simultaneous login requests, an attacker can trigger a software error that forces the server to shut down. This results in a denial of service, preventing legitimate users from accessing their music and media libraries.
Technical details
A race condition (CWE-362) exists in the DAAP login handler of OwnTone Server due to unsynchronized access to the global DAAP session list. The vulnerability is located in the session tracking logic where concurrent access to the `daap_sessions` structure is not properly serialized. An unauthenticated remote attacker can exploit this by flooding the `/login` endpoint with simultaneous requests, leading to a null pointer dereference or memory corruption that crashes the process. The issue was addressed in version 29.1 by implementing a mutex (`daap_session_lck`) to serialize access and switching to session-ID based validation.
Affected products
- OwnTone OwnTone Server 28.4 through 29.0
Timeline
- 2026-03-09: patched: Fix committed to GitHub repository
- 2026-04-21: disclosed: Vulnerability details published by VulnCheck
- 2026-04-22: advisory: CVE-2026-41458 published to NVD