CVE-2026-31804

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_proxy endpoint accepts a user-supplied img parameter and forwards it to Plex Media Server's /photo/:/ transcode transcoder without authentication and without restricting the scheme or host. The endpoint is intentionally excluded from all authentication checks in webstart.py, any value of img beginning with http is passed directly to Plex, this causes the Plex Media Server process, which typically runs on the same host or internal network as Tautulli, with access to RFC-1918 address space, to issue an outbound HTTP request to any attacker-specified URL. This issue has been patched in version 2.17.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tautulli:tautulli:*:*:*:*:*:*:*:*

History

14 Apr 2026, 01:43

Type Values Removed Values Added
CPE cpe:2.3:a:tautulli:tautulli:*:*:*:*:*:*:*:*
First Time Tautulli tautulli
Tautulli
References () https://github.com/Tautulli/Tautulli/releases/tag/v2.17.0 - () https://github.com/Tautulli/Tautulli/releases/tag/v2.17.0 - Release Notes
References () https://github.com/Tautulli/Tautulli/security/advisories/GHSA-qj2f-4c4p-wv97 - () https://github.com/Tautulli/Tautulli/security/advisories/GHSA-qj2f-4c4p-wv97 - Vendor Advisory, Exploit

01 Apr 2026, 14:24

Type Values Removed Values Added
Summary
  • (es) Tautulli es una herramienta de monitoreo y seguimiento basada en Python para Plex Media Server. Antes de la versión 2.17.0, el endpoint /pms_image_proxy acepta un parámetro 'img' proporcionado por el usuario y lo reenvía al transcodificador /photo/:/ transcode de Plex Media Server sin autenticación y sin restringir el esquema o el host. El endpoint está intencionalmente excluido de todas las comprobaciones de autenticación en webstart.py, cualquier valor de 'img' que comience con HTTP se pasa directamente a Plex, esto hace que el proceso de Plex Media Server, que normalmente se ejecuta en el mismo host o red interna que Tautulli, con acceso al espacio de direcciones RFC-1918, emita una solicitud HTTP saliente a cualquier URL especificada por el atacante. Este problema ha sido parcheado en la versión 2.17.0.

30 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 20:16

Updated : 2026-04-14 01:43


NVD link : CVE-2026-31804

Mitre link : CVE-2026-31804

CVE.ORG link : CVE-2026-31804


JSON object : View

Products Affected

tautulli

  • tautulli
CWE
CWE-918

Server-Side Request Forgery (SSRF)