CVE-2026-49220
- EPSS 0.19%
- Veröffentlicht 24.06.2026 18:23:04
- Zuletzt bearbeitet 25.06.2026 16:06:52
Jellyfin is an open source self hosted media server. Prior to 10.11.9, a potential XSS attack exists in Jellyfin which can allow a non-privileged user to execute arbitrary Javascript in the context of a logged-in Administrative user, resulting in num...
CVE-2026-48793
- EPSS 0.36%
- Veröffentlicht 24.06.2026 18:22:18
- Zuletzt bearbeitet 26.06.2026 05:16:28
Jellyfin is an open source self hosted media server. Prior to 10.11.10, a potential FFmpeg argument injection vulnerability exists in the subtitle conversion code path. SubtitleEncoder.ConvertTextSubtitleToSrtInternal (SubtitleEncoder.cs, line 382) i...
CVE-2026-49246
- EPSS 0.26%
- Veröffentlicht 24.06.2026 18:21:25
- Zuletzt bearbeitet 25.06.2026 20:17:12
Jellyfin is an open source self hosted media server. Prior to 10.11.10, a specifically crafted MKV file containing forged filename tags can be leveraged to exploit missing path sanitization during playback. Jellyfin treats the MKV file name tag on MK...
CVE-2026-49247
- EPSS 0.34%
- Veröffentlicht 24.06.2026 18:18:46
- Zuletzt bearbeitet 26.06.2026 05:16:28
Jellyfin is an open source self hosted media server. From 10.9.0 until 10.11.10, the POST /ClientLog/Document endpoint accepts the Authorization header's Client and Version fields and uses them unsanitized as components of the on-disk filename when p...
CVE-2026-35034
- EPSS 0.26%
- Veröffentlicht 14.04.2026 22:31:44
- Zuletzt bearbeitet 23.04.2026 17:42:24
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability in the SyncPlay group creation endpoint (POST /SyncPlay/New), where an authenticated user can create groups with names of unlimit...
CVE-2026-35033
- EPSS 0.32%
- Veröffentlicht 14.04.2026 22:28:47
- Zuletzt bearbeitet 23.04.2026 14:02:45
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions query parameter parsing mechanism. The ParseStreamOpti...
CVE-2026-35032
- EPSS 0.31%
- Veröffentlicht 14.04.2026 22:25:35
- Zuletzt bearbeitet 23.04.2026 14:03:09
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /LiveTv/TunerHosts), where the tuner URL is not validated, allowing local file read via non-HTTP paths...
CVE-2026-35031
- EPSS 0.75%
- Veröffentlicht 14.04.2026 22:18:30
- Zuletzt bearbeitet 23.04.2026 17:44:25
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, allowing path traversal via the f...
CVE-2026-31852
- EPSS 0.45%
- Veröffentlicht 11.03.2026 17:16:58
- Zuletzt bearbeitet 20.03.2026 16:39:05
Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execution via pull requests from forked repositories. Due to the workflow's elevated permissions (nearly al...
CVE-2025-31499
- EPSS 0.62%
- Veröffentlicht 15.04.2025 20:36:24
- Zuletzt bearbeitet 06.10.2025 16:42:39
Jellyfin is an open source self hosted media server. Versions before 10.10.7 are vulnerable to argument injection in FFmpeg. This can be leveraged to possibly achieve remote code execution by anyone with credentials to a low-privileged user. This vul...