Skip to main content
Loading…
    CVE-2026-49130 — Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function within the XSPF playlist plugin that allows attackers to embed literal CR/LF byt — CVE Database · The Intelligence Room