Loading
Jellyfin up to v10.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /Repositories. This vulnerability allows attackers to access network resources and sensitive information via a crafted POST request.
Cite this page
CVE-2023-27161. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2023-27161
Use CWE-918, Jellyfin vendor hub and Jellyfin product page to widen CVE-2023-27161 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-31852, CVE-2026-35031 and CVE-2026-35033 for nearby disclosures in the same product family.