---
id: CVE-2026-100854
title: >-
  AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the
  Liquidsoap API endpoint and incorrectly derives the AutoDJ flag from header
  presence rather than validated value
summary: >-
  AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the
  Liquidsoap API endpoint and incorrectly derives the AutoDJ flag from header
  presence rather than validated value. Users with View station permission can
  inject arb…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-862
vendor: AzuraCast
product: AzuraCast
affected:
  - AzuraCast < 0.23.6
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T02:17:24.747'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100854'
references:
  - url: >-
      https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-4fm3-ggg2-c6qx
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/azuracast-before-0.23.6-metadata-injection-via-liquidsoap-api
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T02:41:45.578Z'
---

## Overview

AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the Liquidsoap API endpoint and incorrectly derives the AutoDJ flag from header presence rather than validated value. Users with View station permission can inject arbitrary now-playing metadata, disrupt live broadcasts, and disclose filesystem paths.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
