Vulnerability Report: GO-2025-3484

Navidrome allows an authentication bypass in Subsonic API with non-existent username in github.com/navidrome/navidrome

For detailed information about this vulnerability, visit https://github.com/navidrome/navidrome/security/advisories/GHSA-c3p4-vm8f-386p or https://nvd.nist.gov/vuln/detail/CVE-2025-27112.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL