
CVE-2026-41457 OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that allows attackers to inject arbitrary SQL expres… https://www.cve.org/CVERecord?id=CVE-2026-41457
Post summary
The post announces a SQL injection flaw in OwnTone Server versions 28.4-29.0 affecting DAAP query and filter handling, providing vulnerability details but no exploit, PoC, or patch information.
