PT-2026-6326 · Navidrome · Navidrome

·

CVE-2026-25579

·

Published

2026-02-04

·

Updated

2026-02-06

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions Navidrome versions prior to 0.60.0
Description Navidrome is a web-based music collection server and streamer. Prior to version 0.60.0, authenticated users can cause a denial of service by providing a large size parameter to the /rest/getCoverArt API endpoint or to a shared-image URL (/share/img/<token>). The server attempts to create an oversized resized image, leading to uncontrolled memory growth. This can trigger the Linux OOM killer, terminating the Navidrome process and causing a service outage. If the system has sufficient memory, the server may write these large images to its cache directory, potentially exhausting disk space. The token variable in the shared-image URL is relevant to the issue.
Recommendations Update Navidrome to version 0.60.0 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25579
GHSA-HRR4-3WGR-68X3
GO-2026-4411
SUSE-SU-2026:0403-1

Affected Products

Navidrome