FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

navidrome -- multiple vulnerabilities

Affected packages
navidrome < 0.60.0

Details

VuXML ID a6effa17-1fd4-4895-8471-d5c684d7807c
Discovery 2026-02-03
Entry 2026-02-07

An XSS vulnerability in the frontend allows a malicious attacker to inject code through the comment metadata of a song to exfiltrate user credentials.

Authenticated users can crash the Navidrome server by supplying an excessively large size parameter to /rest/getCoverArt or to a shared-image URL (/share/img/{token}). When processing such requests, the server attempts to create an extremely large resized image, causing uncontrolled memory growth. This triggers the Linux OOM killer, terminates the Navidrome process, and results in a full service outage.

References

CVE Name CVE-2026-25578
CVE Name CVE-2026-25579
URL https://github.com/navidrome/navidrome/security/advisories/GHSA-hrr4-3wgr-68x3
URL https://github.com/navidrome/navidrome/security/advisories/GHSA-rh3r-8pxm-hg4w