Security Advisories of Vulnerabilities in owntone-server (2025) CVE-2025-57155 Description: NULL pointer dereference in the function in in owntone-server through commit (newer commit after version 28.2) allows remote attackers to cause a Denial of Service. Affected Versions: owntone-server through commit Impact: Denial of Service Fix: Fixed in commit: Link Disclosure Timeline - 2025-07: CVE ID requested - 2025-09: CVE ID assigned CVE-2025-57156 Description: NULL pointer dereference in the function in in owntone-server through commit (newer commit after version 28.12) allows remote attackers to cause a Denial of Service (crash). Affected Versions: owntone-server through commit Impact: Denial of Service Fix: Fixed in commit: Link References - Issue discussion: Link Disclosure Timeline - 2025-07: CVE ID requested - 2025-09: CVE ID assigned CVE-2025-63647 Description: A NULL pointer dereference in the function (src/httpd_daap.c) of owntone-server commit allows attackers to cause a Denial of Service (DoS) via sending a crafted DAAP request to the server. Affected Versions: owntone-server through commit Impact: Denial of Service Fix: Fixed in commit: Link References - Proof of concept: Link Disclosure Timeline - 2025-10: CVE ID requested - 2025-10: CVE ID assigned CVE-2025-63648 Description: A NULL pointer dereference in the function (src/http_dacp.c) of owntone-server commit allows attackers to cause a Denial of Service (DoS) via sending a crafted DACP request to the server. Affected Versions: owntone-server through commit Impact: Denial of Service Fix: Fixed in commit: Link References - Issue discussion: Link Disclosure Timeline - 2025-10: CVE ID requested - 2025-10: CVE ID assigned