Vulnerabilities
Report: CVE-2026-40089 - Sonicverse has Server-Side Request Forgery via user-controlled URLs in dashboard
CVE ID :CVE-2026-40089 Published : April 9, 2026, 8:16 p.m. | 51 minutes ago Description :Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API client (apps/dashboard/lib/api.ts). Installations created using the provided install.sh script (including the one‑liner bash <(curlSeverity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Affected Product:
Docker
Impact:
SSRF