#VU126127 Resource exhaustion in Jellyfin - CVE-2026-35034
Published: April 15, 2026
Jellyfin
Jellyfin
Description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the SyncPlay API endpoint when creating SyncPlay groups with excessively large group names. A remote user can send a specially crafted request to cause a denial of service.
The issue can lock out the endpoint for clients attempting to join SyncPlay groups and may significantly increase memory usage, possibly leading to an out-of-memory crash.