Vulnerability Details CVE-2026-30975
Sonarr is a PVR for Usenet and BitTorrent users. Versions prior to 4.0.16.2942 have an authentication bypass that affected users that had disabled authentication for local addresses (Authentication Required set to: `Disabled for Local Addresses`) without a reverse proxy running in front of Sonarr that didn't not pass through the invalid header. Patches are available in version 4.0.16.2942 in the nightly/develop branch and version 4.0.16.2944 for stable/main releases. Some workarounds are available. Make sure Sonarr's Authentication Required setting is set to `Enabled`, run Sonarr behind a reverse proxy, and/or do not expose Sonarr directly to the internet and instead rely on accessing it through a VPN, Tailscale or a similar solution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 9.4%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2026-30975
-
cpe:2.3:a:sonarr:sonarr:2.0.0.2850
-
cpe:2.3:a:sonarr:sonarr:2.0.0.3004
-
cpe:2.3:a:sonarr:sonarr:2.0.0.3154
-
cpe:2.3:a:sonarr:sonarr:2.0.0.3212
-
cpe:2.3:a:sonarr:sonarr:2.0.0.3243
-
cpe:2.3:a:sonarr:sonarr:2.0.0.3357
-
cpe:2.3:a:sonarr:sonarr:2.0.0.3527
-
cpe:2.3:a:sonarr:sonarr:2.0.0.3530
-
cpe:2.3:a:sonarr:sonarr:2.0.0.3573
-
cpe:2.3:a:sonarr:sonarr:2.0.0.3645
-
cpe:2.3:a:sonarr:sonarr:2.0.0.3732
-
cpe:2.3:a:sonarr:sonarr:2.0.0.3953
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4146
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4230
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4323
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4326
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4370
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4374
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4389
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4409
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4427
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4472
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4613
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4645
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4689
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4748
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4753
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4855
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4913
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4918
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4919
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4928
-
cpe:2.3:a:sonarr:sonarr:2.0.0.4949
-
cpe:2.3:a:sonarr:sonarr:2.0.0.5054
-
cpe:2.3:a:sonarr:sonarr:2.0.0.5085
-
cpe:2.3:a:sonarr:sonarr:2.0.0.5153
-
cpe:2.3:a:sonarr:sonarr:2.0.0.5163
-
cpe:2.3:a:sonarr:sonarr:2.0.0.5225
-
cpe:2.3:a:sonarr:sonarr:2.0.0.5228
-
cpe:2.3:a:sonarr:sonarr:2.0.0.5250
-
cpe:2.3:a:sonarr:sonarr:2.0.0.5301
-
cpe:2.3:a:sonarr:sonarr:2.0.0.5319
-
cpe:2.3:a:sonarr:sonarr:2.0.0.5322
-
cpe:2.3:a:sonarr:sonarr:2.0.0.5344
-
cpe:2.3:a:sonarr:sonarr:3.0.10.1566
-
cpe:2.3:a:sonarr:sonarr:3.0.10.1567
-
cpe:2.3:a:sonarr:sonarr:3.0.5.1144
-
cpe:2.3:a:sonarr:sonarr:3.0.6.1196
-
cpe:2.3:a:sonarr:sonarr:3.0.6.1264
-
cpe:2.3:a:sonarr:sonarr:3.0.6.1266
-
cpe:2.3:a:sonarr:sonarr:3.0.6.1335
-
cpe:2.3:a:sonarr:sonarr:3.0.6.1342
-
cpe:2.3:a:sonarr:sonarr:3.0.7.1477
-
cpe:2.3:a:sonarr:sonarr:3.0.8.1507
-
cpe:2.3:a:sonarr:sonarr:3.0.9.1549
-
cpe:2.3:a:sonarr:sonarr:4.0.0.741
-
cpe:2.3:a:sonarr:sonarr:4.0.0.748
-
cpe:2.3:a:sonarr:sonarr:4.0.0.825
-
cpe:2.3:a:sonarr:sonarr:4.0.0.836
-
cpe:2.3:a:sonarr:sonarr:4.0.0.924
-
cpe:2.3:a:sonarr:sonarr:4.0.1.1014
-
cpe:2.3:a:sonarr:sonarr:4.0.1.1047
-
cpe:2.3:a:sonarr:sonarr:4.0.1.1096
-
cpe:2.3:a:sonarr:sonarr:4.0.1.1114
-
cpe:2.3:a:sonarr:sonarr:4.0.1.1131
-
cpe:2.3:a:sonarr:sonarr:4.0.1.1168
-
cpe:2.3:a:sonarr:sonarr:4.0.1.929
-
cpe:2.3:a:sonarr:sonarr:4.0.1.933
-
cpe:2.3:a:sonarr:sonarr:4.0.1.947
-
cpe:2.3:a:sonarr:sonarr:4.0.1.953
-
cpe:2.3:a:sonarr:sonarr:4.0.1.987
-
cpe:2.3:a:sonarr:sonarr:4.0.10.2544
-
cpe:2.3:a:sonarr:sonarr:4.0.10.2579
-
cpe:2.3:a:sonarr:sonarr:4.0.10.2624
-
cpe:2.3:a:sonarr:sonarr:4.0.10.2656
-
cpe:2.3:a:sonarr:sonarr:4.0.11.2680
-
cpe:2.3:a:sonarr:sonarr:4.0.11.2688
-
cpe:2.3:a:sonarr:sonarr:4.0.11.2697
-
cpe:2.3:a:sonarr:sonarr:4.0.11.2724
-
cpe:2.3:a:sonarr:sonarr:4.0.11.2743
-
cpe:2.3:a:sonarr:sonarr:4.0.11.2762
-
cpe:2.3:a:sonarr:sonarr:4.0.11.2774
-
cpe:2.3:a:sonarr:sonarr:4.0.11.2784
-
cpe:2.3:a:sonarr:sonarr:4.0.11.2793
-
cpe:2.3:a:sonarr:sonarr:4.0.11.2800
-
cpe:2.3:a:sonarr:sonarr:4.0.11.2804
-
cpe:2.3:a:sonarr:sonarr:4.0.11.2815
-
cpe:2.3:a:sonarr:sonarr:4.0.12.2823
-
cpe:2.3:a:sonarr:sonarr:4.0.12.2825
-
cpe:2.3:a:sonarr:sonarr:4.0.12.2849
-
cpe:2.3:a:sonarr:sonarr:4.0.12.2866
-
cpe:2.3:a:sonarr:sonarr:4.0.12.2892
-
cpe:2.3:a:sonarr:sonarr:4.0.12.2900
-
cpe:2.3:a:sonarr:sonarr:4.0.13.2931
-
cpe:2.3:a:sonarr:sonarr:4.0.13.2932
-
cpe:2.3:a:sonarr:sonarr:4.0.13.2933
-
cpe:2.3:a:sonarr:sonarr:4.0.13.2934
-
cpe:2.3:a:sonarr:sonarr:4.0.14.2938
-
cpe:2.3:a:sonarr:sonarr:4.0.14.2939
-
cpe:2.3:a:sonarr:sonarr:4.0.15.2940
-
cpe:2.3:a:sonarr:sonarr:4.0.15.2941
-
cpe:2.3:a:sonarr:sonarr:4.0.2.1183
-
cpe:2.3:a:sonarr:sonarr:4.0.2.1192
-
cpe:2.3:a:sonarr:sonarr:4.0.2.1223
-
cpe:2.3:a:sonarr:sonarr:4.0.2.1262
-
cpe:2.3:a:sonarr:sonarr:4.0.2.1312
-
cpe:2.3:a:sonarr:sonarr:4.0.2.1341
-
cpe:2.3:a:sonarr:sonarr:4.0.2.1367
-
cpe:2.3:a:sonarr:sonarr:4.0.2.1408
-
cpe:2.3:a:sonarr:sonarr:4.0.3.1413
-
cpe:2.3:a:sonarr:sonarr:4.0.3.1442
-
cpe:2.3:a:sonarr:sonarr:4.0.3.1465
-
cpe:2.3:a:sonarr:sonarr:4.0.3.1486
-
cpe:2.3:a:sonarr:sonarr:4.0.4.1491
-
cpe:2.3:a:sonarr:sonarr:4.0.4.1515
-
cpe:2.3:a:sonarr:sonarr:4.0.4.1572
-
cpe:2.3:a:sonarr:sonarr:4.0.4.1616
-
cpe:2.3:a:sonarr:sonarr:4.0.4.1650
-
cpe:2.3:a:sonarr:sonarr:4.0.4.1668
-
cpe:2.3:a:sonarr:sonarr:4.0.4.1692
-
cpe:2.3:a:sonarr:sonarr:4.0.4.1695
-
cpe:2.3:a:sonarr:sonarr:4.0.4.1699
-
cpe:2.3:a:sonarr:sonarr:4.0.5.1710
-
cpe:2.3:a:sonarr:sonarr:4.0.5.1719
-
cpe:2.3:a:sonarr:sonarr:4.0.5.1740
-
cpe:2.3:a:sonarr:sonarr:4.0.5.1760
-
cpe:2.3:a:sonarr:sonarr:4.0.5.1778
-
cpe:2.3:a:sonarr:sonarr:4.0.5.1782
-
cpe:2.3:a:sonarr:sonarr:4.0.5.1791
-
cpe:2.3:a:sonarr:sonarr:4.0.5.1801
-
cpe:2.3:a:sonarr:sonarr:4.0.6.1805
-
cpe:2.3:a:sonarr:sonarr:4.0.6.1820
-
cpe:2.3:a:sonarr:sonarr:4.0.6.1847
-
cpe:2.3:a:sonarr:sonarr:4.0.7.1863
-
cpe:2.3:a:sonarr:sonarr:4.0.7.1868
-
cpe:2.3:a:sonarr:sonarr:4.0.8.1874
-
cpe:2.3:a:sonarr:sonarr:4.0.8.1893
-
cpe:2.3:a:sonarr:sonarr:4.0.8.1902
-
cpe:2.3:a:sonarr:sonarr:4.0.8.1929
-
cpe:2.3:a:sonarr:sonarr:4.0.8.1967
-
cpe:2.3:a:sonarr:sonarr:4.0.8.1988
-
cpe:2.3:a:sonarr:sonarr:4.0.8.2008
-
cpe:2.3:a:sonarr:sonarr:4.0.8.2093
-
cpe:2.3:a:sonarr:sonarr:4.0.8.2158
-
cpe:2.3:a:sonarr:sonarr:4.0.8.2208
-
cpe:2.3:a:sonarr:sonarr:4.0.8.2223
-
cpe:2.3:a:sonarr:sonarr:4.0.9.2244
-
cpe:2.3:a:sonarr:sonarr:4.0.9.2257
-
cpe:2.3:a:sonarr:sonarr:4.0.9.2278
-
cpe:2.3:a:sonarr:sonarr:4.0.9.2300
-
cpe:2.3:a:sonarr:sonarr:4.0.9.2332
-
cpe:2.3:a:sonarr:sonarr:4.0.9.2342
-
cpe:2.3:a:sonarr:sonarr:4.0.9.2386
-
cpe:2.3:a:sonarr:sonarr:4.0.9.2421
-
cpe:2.3:a:sonarr:sonarr:4.0.9.2457
-
cpe:2.3:a:sonarr:sonarr:4.0.9.2513