Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text discloses a new DoS vulnerability (CVE‑2026‑25579) in Navidrome before version 0.60.0 caused by oversized image resizing, with no PoC, exploit, or patch details provided.
CVE@CVEnewDisclosure
The CVE announces a crash vulnerability in Navidrome that requires authentication, with no exploit or patch details provided.
PulsePatch.io@pulsepatchioDisclosure
Navidrome installations are vulnerable to a denial‑of‑service and disk‑exhaustion flaw (CVE‑2026‑25579). No PoC, exploit, or patch information is provided; users are advised to review their deployments.
0day Signal@0dayPublishingDisclosure
The post announces CVE-2026-25579, a denial‑of‑service vulnerability in Navidrome’s image endpoints that can be triggered by simple parameter abuse to cause out‑of‑memory kills and disk exhaustion.