📦 Owntone Server

by Owntone

🔍 What is Owntone Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-38383

CRITICAL CVSS 9.8 Aug 10, 2021

CVE-2021-38383 is a use-after-free vulnerability in OwnTone's net_bind() function that allows attackers to execute arbitrary code or cause denial of service. This affects OwnTone (owntone-server) user...

CVE-2025-63647

HIGH CVSS 7.5 Jan 20, 2026

A NULL pointer dereference vulnerability in owntone-server's parse_meta function allows attackers to crash the server by sending a specially crafted DAAP request, causing denial of service. This affec...

CVE-2025-63648

HIGH CVSS 7.5 Jan 20, 2026

A NULL pointer dereference vulnerability in owntone-server's DACP handling allows attackers to crash the service by sending a specially crafted request. This affects systems running vulnerable version...

CVE-2025-57155

HIGH CVSS 7.5 Jan 20, 2026

A NULL pointer dereference vulnerability in owntone-server's DAAP service allows remote attackers to crash the service by sending specially crafted requests. This affects all systems running vulnerabl...

CVE-2025-57156

HIGH CVSS 7.5 Jan 20, 2026

A NULL pointer dereference vulnerability in owntone-server's DACP reply handling allows remote attackers to crash the service by sending specially crafted requests. This affects all systems running vu...