28,679 Entries 2,229 Sources 5 Verticals Last sync 5 minutes Live
Self-hosted apps

Jellyfin

Jellyfin
v10.11.11 Hotfix empfohlen latest release
06.06.2026

Hotfix empfohlen — 5 offene Regression(en) im Repo · 384 open bugs, 5 Regressions

Upgrade assessment

Sicherheitsrelevant

Zeitnah aktualisieren

25 CVE(s) zuletzt, höchste Schwere: kritisch
5 offene Regression(en) im Repo
384 offene Bug-Tickets

Derived automatically from release, repo and CVE data — no judgment by a language model.

Specsattributes
health{'open_bugs': 384, 'checked_at': '2026-06-08T02:00:34.497300', 'open_regressions': 5}
gh_etagW/"8b2c91693b079e1e44602e0f06c472ede4170ff02dac4ff64584377109b0a65b"
gh_checked_at2026-06-08T03:00:00.127675+00:00
Timelinealle Einträge
Type Ereignis · Quelle Value · Time
CVE
Self-hosted apps High

MoviePilot v2 contains a vulnerability that allows authenticated attackers to target arbitrary internal network services and steal data by bypassing insufficient URL filtering in the image proxy endpoint.

CVE-2026-10107
06.06.2026
CVE
Self-hosted apps Critical

A security vulnerability in Jellystat (a statistics app for Jellyfin) allows authenticated users to inject malicious SQL code, enabling them to read sensitive data or even execute arbitrary commands on the server.

CVE-2026-41167
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Jellyfin versions before 10.11.7 allows authenticated users to create groups with extremely long names, blocking the SyncPlay service for others and potentially causing server crashes due to excessive memory usage.

affects: <10.11.7 · v10.11.11 not affected

CVE-2026-35034
06.06.2026
CVE
Self-hosted apps Critical

Jellyfin media server before version 10.11.7 has a critical security flaw that allows attackers to read arbitrary files from the server without authentication by injecting malicious parameters into video streaming requests.

affects: <10.11.7 · v10.11.11 not affected

CVE-2026-35033
06.06.2026
CVE
Self-hosted apps High

Jellyfin media server before version 10.11.7 has a security flaw that allows logged-in users to read local files and gain admin privileges by exploiting manipulated Live TV settings.

affects: <10.11.7 · v10.11.11 not affected

CVE-2026-35032
06.06.2026
CVE
Self-hosted apps Critical

A critical security vulnerability in Jellyfin Media Server allows administrators or users with subtitle upload permissions to write arbitrary files and ultimately gain complete system control as root user.

affects: <10.11.7 · v10.11.11 not affected

CVE-2026-35031
06.06.2026
CVE
Self-hosted apps Critical

A security flaw in the Anchorr Discord bot allows attackers to inject malicious code into admin browsers, gaining complete system access and control over all connected services including Jellyfin media servers.

CVE-2026-32891
06.06.2026
CVE
Self-hosted apps Critical

A security flaw in the Anchorr Discord bot allows any Discord user to execute malicious code in the administrator's browser and steal all stored passwords and API keys.

CVE-2026-32890
06.06.2026
CVE
Self-hosted apps Critical

A vulnerability in the GitHub Actions workflows of the Jellyfin iOS app allows attackers to execute arbitrary code and gain full repository control, potentially leading to secret theft and supply chain attacks.

CVE-2026-31852
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Seerr, a media manager for Jellyfin and other streaming servers, exposes sensitive user data including API keys for Pushover and Telegram to any authenticated user, regardless of their permission level.

CVE-2026-27793
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Seerr (a media manager for Jellyfin) allows authenticated users to access and modify other users' data because certain API routes lack proper authorization checks.

CVE-2026-27792
06.06.2026
CVE
Self-hosted apps High

A vulnerability in Seerr software allows attackers to register accounts without valid credentials by using their own Jellyfin server, even when Seerr is configured for Plex instead.

CVE-2026-27707
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Jellyfin media servers allows attackers to read arbitrary files from the server, especially on Windows systems. Publicly accessible servers are at risk of sensitive data exposure.

CVE-2021-21402
06.06.2026
CVE
Self-hosted apps Medium

Jellyfin media server contains a Server-Side Request Forgery vulnerability in multiple API endpoints that allows unauthenticated attackers to access internal network services, steal data, and scan networks.

CVE-2021-29490
06.06.2026
CVE
Self-hosted apps Critical

A critical security vulnerability in Jellyfin allows attackers with low-privilege user accounts to execute arbitrary commands on the server by chaining directory traversal, file upload, and cross-site scripting exploits.

CVE-2023-30626
06.06.2026
CVE
Self-hosted apps High

A vulnerability in Jellyfin allows attackers to inject additional commands into FFmpeg calls, enabling arbitrary file reading or overwriting. While technically exploitable without authentication, practical exploitation is highly unlikely as it requires guessing random GUIDs.

CVE-2023-49096
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Jellyfin allows administrators to execute arbitrary programs via network shares by sending a special path to a system endpoint.

CVE-2023-48702
06.06.2026
CVE
Self-hosted apps Medium

Jellyfin media software allows uploading SVG files as profile pictures, enabling attackers to inject malicious SVG files that can steal admin credentials and elevate regular users to administrator privileges.

CVE-2024-43801
06.06.2026
CVE
Self-hosted apps High

Jellyfin media server contains a vulnerability that allows authenticated users to inject malicious commands into FFmpeg, potentially enabling them to execute arbitrary code on the server.

CVE-2025-31499
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Jellyfin allows attackers to spoof their IP address and restart the server without authentication, enabling repeated denial-of-service attacks against the media server.

CVE-2025-32012
06.06.2026
CVE
Self-hosted apps Low

A vulnerability in Jellyfin allows unauthenticated users to request arbitrarily large splash screen images through the Branding API, which can cause memory, CPU, and disk space issues when repeatedly requested, potentially crashing the server.

Advisory
06.06.2026
CVE
Self-hosted apps Critical

A critical security vulnerability in Jellyfin allows users with subtitle upload permissions to write arbitrary files on the server and ultimately execute code as administrator.

CVE-2026-35031
06.06.2026
CVE
Self-hosted apps High

A vulnerability in Jellyfin allows authenticated users to read arbitrary files, forge server requests, and steal the database through an unsecured LiveTV endpoint, enabling them to gain administrator privileges.

CVE-2026-35032
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Jellyfin allows malicious users to create SyncPlay groups with extremely long names, which can block the service and lock out other users.

CVE-2026-35034
06.06.2026
CVE
Self-hosted apps High

A security vulnerability in Jellyfin allows unauthenticated attackers to read arbitrary files from the server by injecting malicious parameters into video streaming requests and extracting file contents through the video output.

CVE-2026-35033
06.06.2026
REL
Self-hosted apps Low Hotfix empfohlen

Jellyfin Server 10.11.11 fixes bugs and adds a lock helper for the UserManager

v10.11.11
06.06.2026
REL
Self-hosted apps High Hotfix empfohlen

Jellyfin Server 10.11.10 fixes multiple security vulnerabilities and resolves issues with UserData cache and user management

v10.11.10
24.05.2026
REL
Self-hosted apps Low Hotfix empfohlen

Jellyfin 10.11.9 fixes several bugs in video encoders, user management and hardware acceleration

v10.11.9
21.05.2026
REL
Self-hosted apps Medium Hotfix empfohlen

Jellyfin 10.11.8 fixes several regressions from version 10.11.7, including issues with subtitles and language filters

v10.11.8
05.04.2026
REL
Self-hosted apps Critical Hotfix empfohlen

Jellyfin Server 10.11.7 fixes multiple critical security vulnerabilities and various bugs

v10.11.7
31.03.2026
REL
Self-hosted apps Low Hotfix empfohlen

Jellyfin 10.11.6 fixes various bugs in search, artist display, library updates and video transcoding

v10.11.6
19.01.2026
REL
Self-hosted apps Medium Hotfix empfohlen

Jellyfin 10.11.5 fixes 17 bugs including database optimizations, image processing issues, and hardware decoding errors

v10.11.5
15.12.2025
REL
Self-hosted apps Low Hotfix empfohlen

Jellyfin 10.11.4 fixes various bugs including crashes on exFAT drives, locked field issues, and HDR stream handling

v10.11.4
01.12.2025
REL
Self-hosted apps Low Hotfix empfohlen

Jellyfin Server 10.11.3 fixes various bugs in metadata processing, file handling and search functionality

v10.11.3
16.11.2025
REL
Self-hosted apps Medium Hotfix empfohlen

Jellyfin 10.11.2 fixes several bugs including security improvements for password resets and corrections for metadata refresh functionality

v10.11.2
03.11.2025
REL
Self-hosted apps Low Hotfix empfohlen

Jellyfin 10.11.1 fixes various bugs in symlink handling, database migrations, video processing and Live TV functionality

v10.11.1
27.10.2025
REL
Self-hosted apps High Breaking

Jellyfin 10.11.0 introduces major new features including system backup and database refactoring with breaking changes

v10.11.0
20.10.2025
REL
Self-hosted apps Hotfix empfohlen

Ninth release candidate of Jellyfin 10.11.0 with bug fixes for ratings, sorting, libraries and performance improvements

v10.11.0-rc9
13.10.2025
REL
Self-hosted apps Critical Hotfix empfohlen

Critical bugfix in RC8 resolves library breakage when upgrading from RC5 to RC7

v10.11.0-rc8
28.09.2025
REL
Self-hosted apps Low Hotfix empfohlen

Seventh release candidate of Jellyfin 10.11.0 with bug fixes for database issues, SkiaSharp rollback and improvements to metadata processing

v10.11.0-rc7
27.09.2025
REL
Self-hosted apps Low Hotfix empfohlen

Jellyfin Server 10.11.0 RC6 fixes anamorphic video detection, improves audio normalization and optimizes database performance

v10.11.0-rc6
25.09.2025
REL
Self-hosted apps Low Hotfix empfohlen

Jellyfin Server 10.11.0 RC5 released with bug fixes for API timeouts, database queries and image processing

v10.11.0-rc5
13.08.2025
REL
Self-hosted apps Low Hotfix empfohlen

Fourth release candidate of Jellyfin 10.11.0 with bug fixes for database migration, trickplay extraction and improved VOB file support

v10.11.0-rc4
03.08.2025
REL
Self-hosted apps Low Hotfix empfohlen

Jellyfin Server 10.11.0 RC3 released with bug fixes for QSV encoding, syncplay groups, music metadata and various other improvements

v10.11.0-rc3
12.07.2025
REL
Self-hosted apps Low Hotfix empfohlen

Jellyfin Server 10.11.0 RC2 released with bug fixes for metadata handling, collections, database queries and file access

v10.11.0-rc2
15.06.2025
REL
Self-hosted apps Low Hotfix empfohlen

First release candidate of Jellyfin 10.11.0 featuring .NET 9 upgrade, improved anime filename recognition and various bug fixes

v10.11.0-rc1
07.06.2025
REL
Self-hosted apps High Breaking

Jellyfin 10.10.7 fixes security vulnerabilities and bugs but requires proper reverse proxy configuration

v10.10.7
05.04.2025
REL
Self-hosted apps Medium Hotfix empfohlen

Jellyfin 10.10.6 fixes several bugs including crashes on Apple Silicon and issues with image encoding and LiveTV

v10.10.6
16.02.2025
REL
Self-hosted apps Low Hotfix empfohlen

Jellyfin Server 10.10.5 fixes various bugs related to file access, subtitles, audio streaming and metadata processing

v10.10.5
25.01.2025
REL
Self-hosted apps Medium Hotfix empfohlen

Jellyfin 10.10.4 fixes various issues with audio/video transcoding, metadata parsing, and EPG caching

v10.10.4
22.01.2025
REL
Self-hosted apps Low Hotfix empfohlen

Jellyfin 10.10.3 fixes issues with file system-based library playlists and reduces the minimum SDK version requirement

v10.10.3
19.11.2024
REL
Self-hosted apps Low Hotfix empfohlen

Jellyfin 10.10.2 fixes various bugs in playlists, trickplay images, transcoding and metadata processing

v10.10.2
16.11.2024
REL
Self-hosted apps Low Hotfix empfohlen

Jellyfin Server 10.10.1 fixes several bugs including audio codec issues, null reference exceptions, and TMDB import problems

v10.10.1
03.11.2024
REL
Self-hosted apps Medium Hotfix empfohlen

Jellyfin 10.10.0 introduces new Media Segments API, Dolby AC-4 decoder, software tonemap filter support and numerous improvements for hardware acceleration and trickplay

v10.10.0
26.10.2024
REL
Self-hosted apps Low Hotfix empfohlen

Jellyfin 10.9.11 fixes several bugs related to subtitle extraction, codec profiles, version names, and chapter images

v10.9.11
07.09.2024
REL
Self-hosted apps Low Hotfix empfohlen

Maintenance update with various bug fixes for image support, codec processing, user interface and stability

v10.9.10
25.08.2024