CVE-2026-86118
gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attackers can repeatedly call the startScan endpoint to force CPU and I/O-intensive filesystem operations, causing denial of service on multi-user instances.
Faiblesse
gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attackers can repeatedly call the startScan endpoint to force CPU and I/O-intensive filesystem operations, causing denial of service on multi-user instances.
Références
- https://github.com/sentriz/gonic
- https://github.com/sentriz/gonic/blob/v0.21.0/server/ctrlsubsonic/ctrl.go
- https://github.com/sentriz/gonic/blob/v0.21.0/server/ctrlsubsonic/handlers_common.go
- https://github.com/sentriz/gonic/releases/tag/v0.22.0
- https://github.com/sentriz/gonic/security/advisories/GHSA-453r-pgfw-h3pq
- https://www.vulncheck.com/advisories/gonic-before-0.22.0-missing-administrator-check-on-the-subsonic-startscan-endpoint
Trouvez la faille avant un attaquant.
Connectez-vous avec GitHub et lancez votre premier audit en moins d'une minute. L'offre gratuite ne nécessite aucune carte bancaire.