← العودة للجدول
CVE-2026-35033
CVE-2026-35033 — VulnCheck: Jellyfin is an open source self hosted media server. Versions prior to
📅 2026-04-14
🔴 Critical 🔥 No VulnCheck Exploit Vulnerability CVSS 9.1

📋 الوصف الكامل

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions query parameter parsing mechanism. The ParseStreamOptions method in StreamingHelpers.cs adds any lowercase query parameter to a dictionary without validation, bypassing the RegularExpression attribute on

💻 الأنظمة المتأثرة

VulnCheck: Jellyfin is

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-35033

📡 المصدر

VulnCheck

✅ الحلول والتخفيف

Update to v10.11.7

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←