← All CVEs NewScan detects
high

CVE-2026-100847

AzuraCast pre-0.23.8 batch: DQL injection via the sortOrder API parameter, plus SSRF, command/code injection and unauthenticated media download

Severity
high
Affected product
AzuraCast
Affected versions
AzuraCast < 0.23.8
Fixed in
AzuraCast 0.23.8
Added to NewScan
2026-09-27
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints AzuraCast from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-27 (/daily-cve). ONE row for the whole 2026-09-27 AzuraCast window rather than eight, on the Bouncy Castle precedent: every id below is cleared by the same upgrade, so eight rows would mean eight findings that all say "upgrade to 0.23.8" - noise, not coverage. CVE-2026-100847 (8.7, arbitrary DQL injected through the sortOrder parameter of AbstractSearchableListAction.php) names the row as the worst with a stated fix. Also covers, all fixed at or below 0.23.8: CVE-2026-100851 (7.2, broken access control on GET /api/station/{id}/vue/profile for View-Station-Page-only users), CVE-2026-100853 (8.2, the public On-Demand download endpoint skips playlist-level access control, so unauthenticated callers fetch media excluded from on-demand), CVE-2026-100848 (7.1, SSRF - a station's Remote Relay URL is validated for syntax and scheme only), CVE-2026-100849 (7.1, SSRF filter bypass in AbstractConnector::getValidUrl webhook validation via hostname and private IPs), CVE-2026-100856 (8.7, code injection in the remote relay password field, incomplete migration from cleanUpString to toRawString, fixed 0.23.6), CVE-2026-100855 (7.1, missing permission check on GET /api/station/{station_id}/file/{id}/play, fixed 0.23.6) and CVE-2026-100857 (8.6, Liquidsoap string-interpolation code injection in ConfigWriter::cleanUpString(), fixed 0.23.4). DELIBERATELY EXCLUDED: CVE-2026-100852 (8.7, unquoted streamer username reaching Liquidsoap process.run) - its advisory says only "through 0.23.x" and names no fix release, so no `lt` written from it can separate a patched build from an unpatched one and claiming it under this range would be a guess. Version-match only: every one of these needs an authenticated station role or mutates the target's config, so none has a safe in-band oracle. VERSION SOURCE, named per the observation-source rule: the tech_signatures `body` row for AzuraCast, which takes the version out of the anonymous /api/openapi.yml `info:` block (measured 0.23.8 against ghcr.io/azuracast/azuracast:latest) - that path was added to packs/paths.json `spec` in the same batch, and without it this key is dead data.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →