CVE-2026-31804Disclosure(tautulli / tautulli)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_proxy endpoint accepts a user-supplied img parameter and forwards it to Plex Media Server's /photo/:/ transcode transcoder without authentication and without restricting the scheme or host. The endpoint is intentionally excluded from all authentication checks in webstart.py, any value of img beginning with http is passed directly to Plex, this causes the Plex Media Server process, which typically runs on the same host or internal network as Tautulli, with access to RFC-1918 address space, to issue an outbound HTTP request to any attacker-specified URL. This issue has been patched in version 2.17.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tautulli

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
tautulli

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-31: 2Technical Details · 2026-03-31: 203-31
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-31804 Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_proxy endpoint accepts a user-supplied img para… https://www.cve.org/CVERecord?id=CVE-2026-31804 ----- Traducción: CVE-2026-31804 Tau… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-31804 affecting Tautulli’s /pms_image_proxy endpoint prior to version 2.17.0, linking to the official CVE record and briefly describing the vulnerability without providing PoC, exploit, or patch details.

    0000038
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31804 Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_proxy endpoint accepts a user-supplied img para… https://www.cve.org/CVERecord?id=CVE-2026-31804

    Post summary

    The post reports that CVE-2026-31804 allows a user‑supplied img parameter via Tautulli's /pms_image_proxy endpoint before v2.17.0, with no mention of PoC, exploitation, patch, or false‑positive status.

    00000154
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptautullitautulli---

Explore more