A NULL pointer dereference in the daapreplyplaylists function (src/httpd_daap.c) of owntone-server commit 3d1652d allows attackers to cause a Denial of Service (DoS) via sending a crafted DAAP request to the server
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26828.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26828.json"
[
{
"source": "https://github.com/owntone/owntone-server/commit/9ac54f0b42491c4862791db4c5368ff80c4000d3",
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"202517628613330064493237889623832646086",
"86504543766115576910313055844551313878",
"127897990241555615322535888581872013260",
"138311711131024837575295135431827919122"
],
"threshold": 0.9
},
"id": "CVE-2026-26828-512d11c6",
"target": {
"file": "src/dmap_common.h"
},
"deprecated": false
},
{
"source": "https://github.com/owntone/owntone-server/commit/9ac54f0b42491c4862791db4c5368ff80c4000d3",
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"function_hash": "46399336861461138490694346352557351697",
"length": 1138.0
},
"id": "CVE-2026-26828-53c9ea15",
"target": {
"function": "parse_meta",
"file": "src/httpd_daap.c"
},
"deprecated": false
},
{
"source": "https://github.com/owntone/owntone-server/commit/9ac54f0b42491c4862791db4c5368ff80c4000d3",
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"333590560745961652894498386167989269793",
"14542809464948504017382720928761227440",
"169823762013010433243534539413248872147",
"100973543517718708521019025810936897970",
"24863460383593515880131787565767501741",
"289606303527353399527041515704550278743",
"234961027075108534208634411505358037164",
"79567594535018285659995054357226097473",
"43159694613143184104949601412309724982",
"284245545291925364006002574005009018808",
"145679684739720757462995377161483705014",
"196601446887348694484499523326821572704",
"146840810782599492037037762841504936650",
"96523930072727154488473481452759880732",
"254886615248911926980983418994103867509",
"150283855879947736285930866212882774927",
"130822320453436551856445774455540014178",
"219042260039515264386298745620275954242",
"99527441706777747307190485857046045217",
"235284077524792325215136297776843528695",
"89187203582548574219080139425539717203",
"249601853111616218638235957281741884509",
"86549034164475679512130072720542560616",
"154341669129047077627515605211303524973",
"32641159645060548805313281164304170187",
"184613363128354858152913798094258506283",
"321174880216959090504499478668721503464",
"183793003462802710379475593140003137512",
"276537986776216129608101661144387642206",
"146960143381697810355835213022297328464",
"320992457708055972940077294298210058808",
"194513625847625670576789893513399567650",
"333074141710635353878506192750459148821",
"238279766017416926091631856183554000652",
"243921218303116852323603391838578213337",
"13372157485604300251057356671060481865",
"302442960093270988605159631263968210813",
"179346148643691992503432501564948436783",
"243690737569506802203799837149823820252",
"33817009885045378762199169437762336101",
"333232168025057068630391611604696717338",
"84586949754859485816499121295623082283",
"125426093311440487900935235632547980950",
"55977112920836556912458786368265597541",
"96382436346367939783970427152650038612",
"177980026696936959293082607200580469596",
"281707473097694933790396583040641110824"
],
"threshold": 0.9
},
"id": "CVE-2026-26828-88bb53bd",
"target": {
"file": "src/httpd_daap.c"
},
"deprecated": false
},
{
"source": "https://github.com/owntone/owntone-server/commit/9ac54f0b42491c4862791db4c5368ff80c4000d3",
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"function_hash": "176663284423098566721199010306751537314",
"length": 100.0
},
"id": "CVE-2026-26828-93f2fff3",
"target": {
"function": "dmap_find_field_wrapper",
"file": "src/dmap_common.c"
},
"deprecated": false
},
{
"source": "https://github.com/owntone/owntone-server/commit/9ac54f0b42491c4862791db4c5368ff80c4000d3",
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"212694168782216057142580190514245597870",
"161960231475286397165031094320410104197",
"287715883219834820966844492542422603309",
"241294662030761872739883761456682429831",
"333708310543915436368768143591572729674",
"176175166168708500269782390209732584722"
],
"threshold": 0.9
},
"id": "CVE-2026-26828-af950d23",
"target": {
"file": "src/dmap_common.c"
},
"deprecated": false
}
]
"2026-07-15T20:28:07Z"