
CVE-2026-41458 OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server b… https://www.cve.org/CVERecord?id=CVE-2026-41458
Post summary
This CVE describes a race condition in OwnTone Server’s DAAP login handler that permits unauthenticated attackers to crash the server; no PoC, exploit code, or patch information is provided.
