Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1.2 and prior, a lenient CORS policy allows attackers to make a cross origin request, reading privileged information. This can be used to leak the admin password. Commit 9215d9ba0f29d62201d3feea9e77dcd274581624 fixes this issue.

Project Subscriptions

Vendors Products
Owncast Project Subscribe
Owncast Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-2659 Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1.2 and prior, a lenient CORS policy allows attackers to make a cross origin request, reading privileged information. This can be used to leak the admin password. Commit 9215d9ba0f29d62201d3feea9e77dcd274581624 fixes this issue.
Github GHSA Github GHSA GHSA-v99w-r56h-g23v Owncast Cross-Site Request Forgery vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 14 Oct 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Owncast Project
Owncast Project owncast
CPEs cpe:2.3:a:owncast_project:owncast:*:*:*:*:*:*:*:*
Vendors & Products Owncast Project
Owncast Project owncast

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T01:03:51.653Z

Reserved: 2024-03-14T16:59:47.611Z

Link: CVE-2024-29026

cve-icon Vulnrichment

Updated: 2024-08-02T01:03:51.653Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-20T22:15:08.557

Modified: 2025-10-14T17:01:44.903

Link: CVE-2024-29026

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses