PT-2026-46259 · Tautulli · Tautulli

·

CVE-2026-43986

·

Published

2026-06-04

·

Updated

2026-06-08

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Tautulli versions prior to 2.17.1
Description Tautulli contains a Server-Side Request Forgery (SSRF) issue where a public endpoint '/image/' resolves entries from image hash lookup and processes them using the same server-side image fetch logic as authenticated image proxying. A low-privilege guest user can insert a malicious external image URL into the lookup table, allowing any unauthenticated external user to trigger server-side fetches to an arbitrary attacker-chosen URL by requesting '/image/.png'. SSRF is a flaw that allows an attacker to induce the server-side application to make requests to an unintended location.
Recommendations Update to version 2.17.1.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43986
GHSA-M6J6-RC2C-8VPM

Affected Products

Tautulli