CVE-2025-57156
NULL pointer dereference in the dacpreplyplayqueueeditclear function in src/httpddacp.c in owntone-server through commit 6d604a1 (newer commit after version 28.12) allows remote attackers to cause a Denial of Service (crash).
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/archersec/security-advisories/blob/master/owntone-server/owntone-server-advisory-2025.md, https://github.com/owntone/owntone-server/issues/1907, https://github.com/archersec/security-advisories/blob/master/owntone-server/owntone-server-advisory-2025.md, https://github.com/owntone/owntone-server/commit/5e4d40ee03ae22ab79534bb1410fa9db96c9fabd, https://github.com/owntone/owntone-server/issues/1907
