Skip to content
Azuracast SSRF Vulnerabilities Expose Systems to Remote Attacks

Azuracast SSRF Vulnerabilities Expose Systems to Remote Attacks

First seen 27 Sep 2026, 19:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 19:57 UTC
  • •Two SSRF vulnerabilities in Azuracast before version 0.23.8.
  • •Attack vectors include hostname and private IP bypass and remote relay URLs.
  • •Immediate update to version 0.23.8 is recommended for all users.

Two critical vulnerabilities have been identified in Azuracast versions prior to 0.23.8, allowing for Server-Side Request Forgery (SSRF) attacks. The first vulnerability enables bypassing SSRF filters through hostname and private IPs, while the second involves exploiting remote relay URLs. These vulnerabilities can lead to unauthorized access to internal services and sensitive data. Affected systems include all versions of Azuracast before 0.23.8, which is widely used for self-hosted web radio stations. No specific CVE numbers were provided in the articles. The vulnerabilities were disclosed on September 27, 2026, and users are urged to update to version 0.23.8 or later to mitigate risks. The current status indicates that real-time alerting systems are in place to monitor the vulnerability landscape.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-27
Vulnerabilities disclosed
Two SSRF vulnerabilities were identified in Azuracast versions prior to 0.23.8, affecting all users.
VulnCheck
2026-09-27
Advisory issued
Users are advised to upgrade to Azuracast version 0.23.8 or later to mitigate the vulnerabilities.
VulnCheck

More articles in this cluster (2)