CVE-2026-25579Disclosure(navidrome / navidrome)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, authenticated users can crash the Navidrome server by supplying an excessively large size parameter to /rest/getCoverArt or to a shared-image URL (/share/img/<token>). When processing such requests, the server attempts to create an extremely large resized image, causing uncontrolled memory growth. This triggers the Linux OOM killer, terminates the Navidrome process, and results in a full service outage. If the system has sufficient memory and survives the allocation, Navidrome then writes these extremely large resized images into its cache directory, allowing an attacker to rapidly exhaust server disk space as well. This issue has been patched in version 0.60.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770CWE-789

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • navidrome

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-04); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
navidrome

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-02-04: 2Mentions · 2026-02-05: 2Technical Details · 2026-02-04: 2Technical Details · 2026-02-05: 202-0402-05
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25579 Navidrome Denial of Service via Oversized Image Resizing in Versions Before 0.60.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25579

    Post summary

    The text discloses a new DoS vulnerability (CVE‑2026‑25579) in Navidrome before version 0.60.0 caused by oversized image resizing, with no PoC, exploit, or patch details provided.

    10000116
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25579 Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, authenticated users can crash the Navidrome server by supplying a… https://www.cve.org/CVERecord?id=CVE-2026-25579

    Post summary

    The CVE announces a crash vulnerability in Navidrome that requires authentication, with no exploit or patch details provided.

    00010141
    56.5K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Navidrome installations are affected by a Denial of Service and disk exhaustion vulnerability (CVE-2026-25579). Review your deployments. #Navidrome #InfoSec #CyberSecurity https://www.pulsepatch.io/posts/navidrome-denial-of-service-disk-exhaustion-cve-2026-25579

    Post summary

    Navidrome installations are vulnerable to a denial‑of‑service and disk‑exhaustion flaw (CVE‑2026‑25579). No PoC, exploit, or patch information is provided; users are advised to review their deployments.

    0000048
    1 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25579: Navidrome affected by Denial of ... Simple parameter abuse in Navidrome's image endpoints triggers OOM kills and disk exhaustion—trivial to automate for gu... https://zerodaysignal.com/vulnerability/CVE-2026-25579 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-25579, a denial‑of‑service vulnerability in Navidrome’s image endpoints that can be triggered by simple parameter abuse to cause out‑of‑memory kills and disk exhaustion.

    0000067
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnavidromenavidrome---

Explore more