CVE-2025-32012
Last modified
CVE-2025-32012 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Jellyfin is an open source self hosted media server. In versions 10.9.0 to before 10.10.7, the /System/Restart endpoint provides administrators the ability to restart their Jellyfin server. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
Jellyfin is an open source self hosted media server. In versions 10.9.0 to before 10.10.7, the /System/Restart endpoint provides administrators the ability to restart their Jellyfin server. This endpoint is intended to be admins-only, but it also authorizes requests from any device in the same local network as the Jellyfin server. Due to the method Jellyfin uses to determine the source IP of a request, an unauthenticated attacker is able to spoof their IP to appear as a LAN IP, allowing them to restart the Jellyfin server process without authentication. This means that an unauthenticated attacker could mount a denial-of-service attack on any default-configured Jellyfin server by simply sending the same spoofed request every few seconds to restart the server over and over. This method of IP spoofing also bypasses some security mechanisms, cause a denial-of-service attack, and possible bypass the admin restart requirement if combined with remote code execution. This issue is patched in version 10.10.7.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jellyfin | Jellyfin | >= 10.9.0, < 10.10.7 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-32012?
How severe is CVE-2025-32012?
How do I fix CVE-2025-32012?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-32007Out-of-bounds read for some TDX before version tdx module 1.…5.6
- CVE-2025-32008Out-of-bounds write in the firmware for the Intel(R) AMT and…8.7
- CVE-2025-32009Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-3201The Contact Form builder with drag & drop for WordPress Wor…5.9
- CVE-2025-32010A stack-based buffer overflow vulnerability exists in the Cl…9.8
- CVE-2025-32011KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authent…9.8
- CVE-2025-32013LNbits is a Lightning wallet and accounts system. A Server-S…7.5
- CVE-2025-32014estree-util-value-to-estree converts a JavaScript value to a…6.9
- CVE-2025-32015FreshRSS is a self-hosted RSS feed aggregator. Prior to vers…6.7
- CVE-2025-32016Microsoft Identity Web is a library which contains a set of …4.7
- CVE-2025-32017Umbraco is a free and open source .NET content management sy…8.8
- CVE-2025-32018Cursor is a code editor built for programming with AI. In ve…8
Are you affected by CVE-2025-32012?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
