phanan/koel
Packagist7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting phanan/koelpage 1 of 1
- CVE-2021-33563HIGHCVSS 7.5EG 7.5✓ Fixed in 5.1.42021-05-24
vulnerable: 1.0.0-beta ... v5.1.3 (47 versions)
Koel before 5.1.4 lacks login throttling, lacks a password strength policy, and shows whether a failed login attempt had a valid username. This might make brute-force attacks easier.
- CVE-2026-47260HIGHCVSS 7.7EG 7.7✓ Fixed in 9.3.52026-05-29
vulnerable: 1.0.0-beta ... v9.3.4 (162 versions)
Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the podcast feed URL via the SafeUrl rule (DNS resolution + public IP check), but the individual episode <enclosure url="..."> values extracted fr…
- CVE-2026-50552MEDIUMCVSS 6.3EG 6.3✓ Fixed in 9.7.12026-06-12
vulnerable: 1.0.0-beta ... v9.7.0 (170 versions)
Koel is a free, open-source music streaming solution. Prior to version 9.7.1, Koel contains a Server-Side Request Forgery (SSRF) vulnerability in the radio station creation endpoint (POST /api/radio/stations). The url field validation rule…
- CVE-2026-54491HIGHCVSS 7.1EG 7.1✓ Fixed in 9.7.12026-07-15
vulnerable: 1.0.0-beta ... v9.7.0 (170 versions)
Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths ### Summary The fix for **CVE-2026-47260** (v9.3.5) added an **initial** `isSafeUrl()` check to several fetchers (`synchronizeEpisodes`, `getStreama…
- CVE-2026-54492MEDIUMCVSS 4.3EG 4.3✓ Fixed in 9.7.02026-07-15
vulnerable: 1.0.0-beta ... v9.6.0 (169 versions)
Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation ### Summary Koel `v9.6.0` protects the regular podcast subscription API with `SafeUrl`, but the Subsonic-compatible `createPodcastChannel.view` route does not apply the …
- CVE-2026-54493HIGHCVSS 7.7EG 7.7✓ Fixed in 9.7.02026-07-15
vulnerable: 1.0.0-beta ... v9.6.0 (169 versions)
Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations ### Summary Koel v9.6.0 validates radio station URLs on the regular web API, but the Subsonic-compatible radio endpoints do not apply the same SSRF protections. An au…
- CVE-2026-54494MEDIUMEG 0.0✓ Fixed in 9.7.12026-07-15
vulnerable: 1.0.0-beta ... v9.7.0 (170 versions)
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4 ## Summary Koel's outbound-URL guard `App\Helpers\Network:…
Check whether phanan/koel is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for phanan/koel CVEs against the assets you own.
Start Free Scan →