CVE-2026-40089·Docker vulnerability
Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API client (apps/dashboard/lib/api.ts). Installations created using the provided install.sh script (including the one‑liner bash <(curl -fsSL https://sonicverse.short.gy/install-audiostack)) are affected. In these deployments, the dashboard accepts user-controlled URLs and passes them directly to a server-side HTTP client without sufficient validation. An authenticated operator can abuse this to make arbitrary HTTP requests from the dashboard backend to internal or external systems. This vulnerability is fixed with commit cb1ddbacafcb441549fe87d3eeabdb6a085325e4.
- Severity
- critical
- Software
- Docker
- Fixed in
- 1.7.2
- Published
- 2026-04-09
Affected versions
Until: 1.7.2
Fixed in: 1.7.2
How to fix this CVE
Update Docker to version 1.7.2 or later to patch the SSRF vulnerability in the Sonicverse Radio Audio Streaming Stack dashboard. The vulnerability allows authenticated operators to make arbitrary HTTP requests from the dashboard backend by bypassing URL validation in the API client. Immediately apply this update to all affected installations, particularly those deployed via the official install.sh script.
sudo dnf update docker-ce -y && sudo systemctl restart dockerDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST /api/[^\s]+ with user-controlled 'url' parameter pointing to internal IP ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or external domains; response time anomalies indicating backend HTTP requests; dashboard logs containing 'fetch|curl|request' followed by internal service names or metadata endpointsWAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement WAF rules to block API requests where the 'url' parameter contains internal IP addresses, private network CIDR blocks, localhost variants (127.0.0.1, ::1), or cloud metadata endpoints (169.254.169.254, 10.0.0.0/8). Enforce strict URL schema validation (http/https only) and maintain an allowlist of permitted target domains if URL requests are business-critical.How to check if you are affected
- Check installed Docker version: docker --version or docker version --format '{{.Server.Version}}'
- Verify Sonicverse dashboard is running: docker ps | grep -i sonicverse or check docker-compose ps in the deployment directory
- Examine dashboard API logs for unusual HTTP requests: docker logs <container_name> | grep -i 'http\|request\|url' to identify outbound requests to unexpected destinations
- Confirm patch applied by checking the git commit hash: git log --oneline | head -5 should show cb1ddbacafcb441549fe87d3eeabdb6a085325e4 or later in the Sonicverse repository
FAQ
What is CVE-2026-40089?
CVE-2026-40089 is a Server-Side Request Forgery (SSRF) vulnerability in the Sonicverse Radio Audio Streaming Stack dashboard that allows authenticated operators to bypass URL validation and make arbitrary HTTP requests from the backend server to internal or external systems.
Is CVE-2026-40089 being actively exploited?
According to CISA, CVE-2026-40089 is not currently listed in the Known Exploited Vulnerabilities (KEV) catalog and no public exploits are available, though the vulnerability is critical in severity.
What versions of Docker are affected by CVE-2026-40089?
Sonicverse versions up to and including 1.7.1 are affected when deployed with Docker; version 1.7.2 and later contain the fix.
How do I check if my server is vulnerable to CVE-2026-40089?
Run 'docker ps --format "table {{.Names}}\t{{.Image}}"' to list running containers and identify Sonicverse deployments, then check the image tag against version 1.7.2 or later.
Does Defensia detect CVE-2026-40089?
Yes — Defensia's CVE advisory scanner compares installed Docker and containerized application versions against the NVD database. If Sonicverse is detected on a monitored server, CVE-2026-40089 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-40089. Free for 1 server.
Get started free