CVE List

CVE-2025-57156

Critical 7.5

NULL pointer dereference in the dacp_reply_playqueueedit_clear function in src/httpd_dacp.c in owntone-server through commit 6d604a1 (newer commit after version 28.12) allows remote attackers to cause a Denial of Service (crash).

Published January 20, 2026.

Affected software

Get alerts for Owntone Project Owntone

Reference links