CVE-2026-31804
Last modified
CVE-2026-31804 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_proxy endpoint accepts a user-supplied img parameter and forwards it to Plex Media Server's /photo/:/ transcode transcoder without authentication and without restricting the scheme or host. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_proxy endpoint accepts a user-supplied img parameter and forwards it to Plex Media Server's /photo/:/ transcode transcoder without authentication and without restricting the scheme or host. The endpoint is intentionally excluded from all authentication checks in webstart.py, any value of img beginning with http is passed directly to Plex, this causes the Plex Media Server process, which typically runs on the same host or internal network as Tautulli, with access to RFC-1918 address space, to issue an outbound HTTP request to any attacker-specified URL. This issue has been patched in version 2.17.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tautulli | Tautulli | < 2.17.0 |
References
- https://github.com/Tautulli/Tautulli/security/advisories/GHSA-qj2f-4c4p-wv97Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-31804?
How severe is CVE-2026-31804?
How do I fix CVE-2026-31804?
Are you affected by CVE-2026-31804?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
