CVE-2025-44560Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-11)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-10: 1Mentions · 2026-04-11: 2Technical Details · 2026-04-10: 1Technical Details · 2026-04-11: 204-1004-11
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-101
General1
2026-04-112
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-44560 owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking. https://www.cve.org/CVERecord?id=CVE-2025-44560

    Post summary

    The text announces a buffer overflow vulnerability in owntone-server version 2ca10d9 linked to missing recursive checks, providing basic technical details without offering PoC, exploitation tools, patches, or claims of active use.

    00010301
    57.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-44560 owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking. https://www.cve.org/CVERecord?id=CVE-2025-44560 ----- Traducción: CVE-2025-44560 owntone-server 2ca10d9 es vulnerable a desbordamiento de búfer debido a la falta … http://infoflow.cloud`

    Post summary

    This post announces the presence of a buffer‑overflow vulnerability (CVE‑2025‑44560) in owntone‑server, providing a brief technical description and linking to the CVE entry.

    00000314
    71 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-44560 Buffer Overflow Vulnerability in Owntone-Server 2ca10d9 Due to Insufficient Recursive Checking https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-44560

    Post summary

    The brief post highlights a buffer overflow flaw in Owntone-Server, but offers no evidence of a PoC, active exploitation, patch, or detailed technical mapping beyond the overflow description.

    00000128
    4.0K followersView on X

Explore more