Vulnerability record · CVE-2021-29490 · published 6 May 2021
CVE-2021-29490: Jellyfin unauthenticated SSRF via imageUrl parameter
Jellyfin · Jellyfin
Jellyfin versions prior to 10.7.3 are vulnerable to unauthenticated server-side request forgery through the imageUrl parameter. An attacker can make the Jellyfin server issue HTTP GET requests to internal or external resources reachable from it. The flaw is patched in 10.7.3.
Description
Jellyfin is a free software media system that provides media from a dedicated server to end-user devices via multiple apps. Verions prior to 10.7.3 vulnerable to unauthenticated Server-Side Request Forgery (SSRF) attacks via the imageUrl parameter. This issue potentially exposes both internal and external HTTP servers or other resources available via HTTP `GET` that are visible from the Jellyfin server. The vulnerability is patched in version 10.7.3. As a workaround, disable external access to the API endpoints `/Items/*/RemoteImages/Download`, `/Items/RemoteSearch/Image` and `/Images/Remote` via reverse proxy, or limit to known-friendly IPs.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable SSRF with a very high EPSS score, though limited to low confidentiality impact and no known in-the-wild exploitation.
What it is
Jellyfin versions prior to 10.7.3 are vulnerable to unauthenticated server-side request forgery through the imageUrl parameter. An attacker can make the Jellyfin server issue HTTP GET requests to internal or external resources reachable from it. The flaw is patched in 10.7.3.
Impact
An attacker gains the ability to probe and retrieve content from internal and external HTTP services visible to the Jellyfin server, potentially exposing resources not otherwise reachable. The CVSS vector shows only low confidentiality impact with no integrity or availability effect.
Attack surface
Reachable over the network through the imageUrl parameter on the API endpoints /Items/*/RemoteImages/Download, /Items/RemoteSearch/Image and /Images/Remote. No authentication or user interaction is required per the CVSS vector (PR:N, UI:N).
Exploitation
Not listed in CISA KEV and no ransomware usage documented, but EPSS is high at roughly 0.70 (99th percentile), indicating elevated likelihood of attempted exploitation. The only references are the vendor advisory tagged Patch and Third Party Advisory, with no public exploit reference supplied.
What to do
- Upgrade Jellyfin to version 10.7.3 or later.
- If patching is not immediate, block external access to /Items/*/RemoteImages/Download, /Items/RemoteSearch/Image and /Images/Remote at the reverse proxy.
- Restrict those endpoints to known-friendly source IPs where external access cannot be fully removed.
- Segment the Jellyfin host so it cannot reach sensitive internal HTTP services.
- Monitor and log outbound HTTP requests originating from the Jellyfin server.
Detection
- Review Jellyfin and reverse proxy logs for requests to the three affected image endpoints with unusual or external imageUrl values.
- Alert on outbound HTTP GET requests from the Jellyfin host to internal RFC1918 addresses or unexpected external hosts.
- Baseline normal imageUrl destinations and flag deviations, especially repeated requests to metadata or loopback addresses.
- Correlate Jellyfin access logs with network egress logs to identify SSRF-style request patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/jellyfin/jellyfin/security/advisories/GHSA-rgjw-4fwc-9v96 | PatchThird Party Advisory |
| https://github.com/jellyfin/jellyfin/security/advisories/GHSA-rgjw-4fwc-9v96 | PatchThird Party Advisory |
Track CVE-2021-29490 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-29490), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.