Detects Sonarr instances before version 4.0.16.2942 where the ASP.NET ForwardedHeadersMiddleware trusts X-Forwarded-For from any source. When 'Disabled for Local Addresses' auth is configured, an attacker spoofs the header with a private IP (e.g. 192.168.1.1) to bypass login entirely. The /initialize.json endpoint then exposes the full API key, granting complete control over downloads, media libraries, and settings.
Is your app exploitable through CVE-2026-30975?
Scan your domain free