VYPR
High severity8.1NVD Advisory· Published Mar 25, 2026· Updated Jun 17, 2026

CVE-2026-30975

CVE-2026-30975

Description

Sonarr is a PVR for Usenet and BitTorrent users. Versions prior to 4.0.16.2942 have an authentication bypass that affected users that had disabled authentication for local addresses (Authentication Required set to: Disabled for Local Addresses) without a reverse proxy running in front of Sonarr that didn't not pass through the invalid header. Patches are available in version 4.0.16.2942 in the nightly/develop branch and version 4.0.16.2944 for stable/main releases. Some workarounds are available. Make sure Sonarr's Authentication Required setting is set to Enabled, run Sonarr behind a reverse proxy, and/or do not expose Sonarr directly to the internet and instead rely on accessing it through a VPN, Tailscale or a similar solution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Sonarr/Sonarr3 versions
    cpe:2.3:a:sonarr:sonarr:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:sonarr:sonarr:*:*:*:*:*:*:*:*range: <4.0.16.2942
    • (no CPE)range: <4.0.16.2942
    • (no CPE)range: < 4.0.16.2942

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.