← Vulnerability feed

Vulnerability record · CVE-2021-29490 · published 6 May 2021

CVE-2021-29490: Jellyfin unauthenticated SSRF via imageUrl parameter

Jellyfin · Jellyfin

Jellyfin versions prior to 10.7.3 are vulnerable to unauthenticated server-side request forgery through the imageUrl parameter. An attacker can make the Jellyfin server issue HTTP GET requests to internal or external resources reachable from it. The flaw is patched in 10.7.3.

5.8 CVSS 3.1 Medium EPSS 70% · top 0.6% CWE-918 · Server-side request forgery (SSRF)
5.8CVSS 3.1 base score, v2 5.0
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Jellyfin is a free software media system that provides media from a dedicated server to end-user devices via multiple apps. Verions prior to 10.7.3 vulnerable to unauthenticated Server-Side Request Forgery (SSRF) attacks via the imageUrl parameter. This issue potentially exposes both internal and external HTTP servers or other resources available via HTTP `GET` that are visible from the Jellyfin server. The vulnerability is patched in version 10.7.3. As a workaround, disable external access to the API endpoints `/Items/*/RemoteImages/Download`, `/Items/RemoteSearch/Image` and `/Images/Remote` via reverse proxy, or limit to known-friendly IPs.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated network-reachable SSRF with a very high EPSS score, though limited to low confidentiality impact and no known in-the-wild exploitation.

What it is

Jellyfin versions prior to 10.7.3 are vulnerable to unauthenticated server-side request forgery through the imageUrl parameter. An attacker can make the Jellyfin server issue HTTP GET requests to internal or external resources reachable from it. The flaw is patched in 10.7.3.

Impact

An attacker gains the ability to probe and retrieve content from internal and external HTTP services visible to the Jellyfin server, potentially exposing resources not otherwise reachable. The CVSS vector shows only low confidentiality impact with no integrity or availability effect.

Attack surface

Reachable over the network through the imageUrl parameter on the API endpoints /Items/*/RemoteImages/Download, /Items/RemoteSearch/Image and /Images/Remote. No authentication or user interaction is required per the CVSS vector (PR:N, UI:N).

Exploitation

Not listed in CISA KEV and no ransomware usage documented, but EPSS is high at roughly 0.70 (99th percentile), indicating elevated likelihood of attempted exploitation. The only references are the vendor advisory tagged Patch and Third Party Advisory, with no public exploit reference supplied.

What to do

  • Upgrade Jellyfin to version 10.7.3 or later.
  • If patching is not immediate, block external access to /Items/*/RemoteImages/Download, /Items/RemoteSearch/Image and /Images/Remote at the reverse proxy.
  • Restrict those endpoints to known-friendly source IPs where external access cannot be fully removed.
  • Segment the Jellyfin host so it cannot reach sensitive internal HTTP services.
  • Monitor and log outbound HTTP requests originating from the Jellyfin server.

Detection

  • Review Jellyfin and reverse proxy logs for requests to the three affected image endpoints with unusual or external imageUrl values.
  • Alert on outbound HTTP GET requests from the Jellyfin host to internal RFC1918 addresses or unexpected external hosts.
  • Baseline normal imageUrl destinations and flag deviations, especially repeated requests to metadata or loopback addresses.
  • Correlate Jellyfin access logs with network egress logs to identify SSRF-style request patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-29490 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-31852Jellyfin improper privilege management vulnerabilityJellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execut…EPSS 0.62%9.3CVE-2026-35033Jellyfin argument injection vulnerabilityJellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpe…EPSS 0.52%8.8CVE-2026-35031Jellyfin improper input validation vulnerabilityJellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /V…EPSS 0.92%8.8CVE-2023-49096Jellyfin argument injection vulnerabilityJellyfin is a Free Software Media System for managing and streaming media. In affected versions there is an argument injection in the VideosControlle…EPSS 1.3%8.8CVE-2022-35909Jellyfin vulnerabilityIn Jellyfin before 10.8, the /users endpoint has incorrect access control for admin functionality.EPSS 1.6%8.6CVE-2026-35032Jellyfin server-side request forgery (ssrf) vulnerabilityJellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /…EPSS 0.38%8.1CVE-2023-30626Jellyfin path traversal vulnerabilityJellyfin is a free-software media system. Versions starting with 10.8.0 and prior to 10.8.10 and prior have a directory traversal vulnerability insid…EPSS 2.0%7.6CVE-2025-31499Jellyfin argument injection vulnerabilityJellyfin is an open source self hosted media server. Versions before 10.10.7 are vulnerable to argument injection in FFmpeg. This can be leveraged to…EPSS 0.79%

Source: NIST National Vulnerability Database (record CVE-2021-29490), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.