๐Ÿ” CVE Alert

CVE-2026-35034

MEDIUM 6.5

Jellyfin: Potential Application DoS from excessively large SyncPlay group names

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
12th

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability in the SyncPlay group creation endpoint (POST /SyncPlay/New), where an authenticated user can create groups with names of unlimited size due to insufficient input validation. By sending large payloads combined with arbitrary group IDs, an attacker can lock out the endpoint for other clients attempting to join SyncPlay groups and significantly increase the memory usage of the Jellyfin process, potentially leading to an out-of-memory crash. This issue has been fixed in version 10.11.7.

CWE CWE-400
Vendor jellyfin
Product jellyfin
Published Apr 14, 2026
Last Updated Apr 15, 2026
Stay Ahead of the Next One

Get instant alerts for jellyfin jellyfin

Be the first to know when new medium vulnerabilities affecting jellyfin jellyfin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

jellyfin / jellyfin
< 10.11.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jellyfin/jellyfin/security/advisories/GHSA-v2jv-54xj-h76w github.com: https://github.com/jellyfin/jellyfin/releases/tag/v10.11.7