VYPR
Medium severity4.0NVD Advisory· Published Mar 30, 2026· Updated Apr 14, 2026

CVE-2026-31804

CVE-2026-31804

Description

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_proxy endpoint accepts a user-supplied img parameter and forwards it to Plex Media Server's /photo/:/ transcode transcoder without authentication and without restricting the scheme or host. The endpoint is intentionally excluded from all authentication checks in webstart.py, any value of img beginning with http is passed directly to Plex, this causes the Plex Media Server process, which typically runs on the same host or internal network as Tautulli, with access to RFC-1918 address space, to issue an outbound HTTP request to any attacker-specified URL. This issue has been patched in version 2.17.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Tautulli/Tautulli2 versions
    cpe:2.3:a:tautulli:tautulli:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:tautulli:tautulli:*:*:*:*:*:*:*:*range: <2.17.0
    • (no CPE)range: <2.17.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.