Skip to content
High-Risk SSRF Vulnerabilities in AzuraCast Webhook and Remote Relay Features

High-Risk SSRF Vulnerabilities in AzuraCast Webhook and Remote Relay Features

First seen 27 Sep 2026, 19:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 19:57 UTC
  • •AzuraCast has critical SSRF vulnerabilities affecting webhook and remote relay features.
  • •CVE-2026-100849 allows low-privileged users to exploit internal network services.
  • •No patches are available, increasing the risk for internet-accessible deployments.

AzuraCast, a self-hosted web radio management suite, has been found to have critical server-side request forgery (SSRF) vulnerabilities in its webhook and remote relay functionalities. The vulnerabilities, identified as CVE-2026-100849, allow users with limited permissions to configure webhooks and remote relays that can target internal network services, potentially leading to data exposure and internal reconnaissance. The webhook URL validation only rejects literal link-local IP addresses, while the remote relay feature lacks any host/IP restrictions. Attackers can exploit these vulnerabilities if they have access to the management interface and the necessary low-level permissions. As of the advisory date, no patched version is available, making the risk particularly high for internet-accessible deployments. Security professionals are urged to review webhook configurations and restrict access to trusted users. The vulnerabilities were disclosed on September 27, 2026, and are currently unpatched.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-27
CVE-2026-100849 published
AzuraCast disclosed a critical SSRF vulnerability affecting webhook and remote relay functionalities.
Redpacketsecurity
2026-09-27
Vulnerability details confirmed
The vulnerabilities allow users with limited permissions to configure webhooks and remote relays targeting internal services.
github.com
2026-09-27
No patches available
As of the advisory date, no patched version of AzuraCast is available to mitigate the vulnerabilities.
Redpacketsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2026-100849 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed