VDB
CVE-2025-63648
CVE-2025-63648
PUBLISHED
CVSS 8.699999809265137 HIGH
A NULL pointer dereference in the dacp_reply_playqueueedit_move function (src/httpd_dacp.c) of owntone-server commit b7e385f allows attackers to cause a Denial of Service (DoS) via sending a crafted DACP request to the server.
EPSS 0.34% · 26.3th percentile
Risk Scores
CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.34%
26.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a, n/a |
| owntone | owntone_server | 0, 0 |
Timeline
- Jan 20, 2026 CVE Published
- Jan 21, 2026 EPSS Score
- Jan 21, 2026 CVE Updated
- Jan 21, 2026 PoC Published
- Jan 24, 2026 EPSS Score
- Jan 27, 2026 EPSS Score
- Jan 30, 2026 EPSS Score
- Feb 1, 2026 EPSS Score
- Feb 4, 2026 EPSS Score
- Feb 7, 2026 EPSS Score
- Feb 10, 2026 EPSS Score
- Feb 13, 2026 EPSS Score
References
- https://github.com/owntone/owntone-server/issues/1933 discussion
- https://github.com/owntone/owntone-server/commit/5f526c7a7e08c567a5c72421d74a79dafdd07621 fix
- https://github.com/archersec/security-advisories/blob/master/owntone-server/owntone-server-advisory-2025.md exploit
- https://nvd.nist.gov/vuln/detail/CVE-2025-63648 advisory