CVE-2025-57156: Owntone Server
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
NULL pointer dereference in the dacp_reply_playqueueedit_clear function in src/httpd_dacp.c in owntone-server through commit 6d604a1 (newer commit after version 28.12) allows remote attackers to cause a Denial of Service (crash).
Affected products
- Owntone Owntone Server: up to and including 28.12
Published 2026-01-20. Last modified 2026-06-17.