PT-2026-44496 · Unknown+1 · Music Player Daemon+1

Daniele Berardinelli

+1

·

Published

2026-05-28

·

Updated

2026-05-28

·

CVE-2026-49129

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Music Player Daemon (MPD) versions prior to 0.24.11
Description A server-side request forgery (SSRF) issue exists in the CurlInputPlugin. The CURLOPT FOLLOWLOCATION option is enabled without specifying CURLOPT REDIR PROTOCOLS STR, which allows unauthenticated attackers to bypass http/https scheme restrictions. By using a malicious HTTP server to redirect requests to non-HTTP protocols—such as gopher, ftp, sftp, ldap, dict, rtmp, or rtsp—attackers can interact with internal or restricted network services. This is possible on systems using libcurl versions prior to 7.85.0. The issue can be triggered via MPD commands that initiate URL fetches, specifically add, readcomments, albumart, readpicture, or load.
Recommendations Update to version 0.24.11 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-49129

Affected Products

Music Player Daemon
Libcurl