All verified exploits

CVE-2026-30975 Authentication Bypass via Forged X-Forwarded-For

Deterministic critical Sonarr Added cve-verified-cve-2026-30975

Detects Sonarr instances before version 4.0.16.2942 where the ASP.NET ForwardedHeadersMiddleware trusts X-Forwarded-For from any source. When 'Disabled for Local Addresses' auth is configured, an attacker spoofs the header with a private IP (e.g. 192.168.1.1) to bypass login entirely. The /initialize.json endpoint then exposes the full API key, granting complete control over downloads, media libraries, and settings.

Is your app exploitable through CVE-2026-30975?

Scan your domain free