🎧 Your Personal Streaming Service https://www.navidrome.org
  • Go 81.5%
  • JavaScript 15.1%
  • Rust 2.2%
  • Go Template 0.5%
  • Makefile 0.3%
  • Other 0.4%
Find a file
Deluan Quintão 237276efcd
fix(artwork): block private and loopback addresses in remote image fetches (#6181)
* fix(artwork): block private and loopback addresses in remote image fetches

fromURL fetched any URL with a plain HTTP client, and two untrusted inputs reach it. A playlist
can set #EXTALBUMARTURL to an http(s) URL, which the artwork worker later fetches when
EnableM3UExternalAlbumArt is on, so any user who can import a playlist controls the target.
Metadata agents, including WASM plugins without the http permission, return image URLs that the
core fetches too. Either path could make the server request loopback, LAN or link-local
addresses and store the response as artwork that is served back.

Add httpclient.NewExternal, which dials through a net.Dialer Control hook that rejects private,
loopback, link-local and unspecified addresses. The check runs at dial time on the resolved IP,
so DNS names, redirects and DNS rebinding are covered. fromURL now uses one shared client built
with it and treats a refused address as a definitive miss, so the item settles absent instead of
retrying and tripping the agent's circuit breaker. httpclient.New is unchanged for the other callers.

The IP classification moves from plugins to the new utils/netguard package, shared by the plugin
host client and the new constructor. The artwork test suite swaps in a client that allows
loopback so existing specs can keep using httptest servers; the fromURL specs use the production
client to assert the refusal.

* fix(httpclient): keep dialing a configured proxy in the guarded client

The guard runs on the resolved address, and with HTTP_PROXY set that address is the proxy, not
the image host. A proxy on a private address would have had every remote artwork fetch refused,
and a refusal settles the item as absent, so covers would silently disappear for those setups.

Dial the configured proxy endpoint directly and keep the guard for every other dial. A proxy
relays the request itself, so it is the operator's egress policy, the same one every other
httpclient.New caller already goes through.

* fix(httpclient): exempt only the hop that actually goes through the proxy

The exemption matched any dial to a configured proxy's address, but net/http never proxies
loopback targets, so a URL aimed at a loopback proxy was dialed directly and skipped the guard.
That let an image URL reach that one address.

Tag each request with the proxy it resolves to and exempt a dial only when it is that hop.
Redirects re-enter the RoundTripper, so every hop is tagged on its own.
2026-09-20 20:46:46 -04:00
.devcontainer chore(deps): upgrade to Go 1.27 (#5990) 2026-08-30 12:43:15 -04:00
.github ci: comment coverage on pull requests from forks (#6065) 2026-09-01 07:32:28 -04:00
adapters fix(lastfm): double-encode plus signs in artist and track names (#6158) 2026-09-17 07:29:56 -04:00
cmd feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00
conf feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00
consts feat: validate all configuration durations (#6002) 2026-09-01 21:16:14 -04:00
contrib fix(contrib): added missing hyphen in OpenRC script that caused crashes on startup (#5906) 2026-08-08 15:40:05 -04:00
core fix(artwork): block private and loopback addresses in remote image fetches (#6181) 2026-09-20 20:46:46 -04:00
db feat(cli): add 'doctor' and 'search rebuild' commands to recover from FTS5 corruption (#6069) 2026-09-11 22:26:28 -04:00
git feat(plugins): experimental support for plugins (#3998) 2025-06-22 20:45:38 -04:00
log refactor(log): replace sort with slices.SortFunc and use atomic for currentLevel 2026-09-06 13:08:05 -04:00
model feat(smartplaylists): add support for referencing playlists using paths (#5187) 2026-09-19 21:05:58 -04:00
persistence fix(test): stop the Windows test job from failing at random (#6182) 2026-09-20 15:27:20 -04:00
plugins fix(artwork): block private and loopback addresses in remote image fetches (#6181) 2026-09-20 20:46:46 -04:00
release fix(release): repair root-owned artwork and plugins folders on upgrade (#6143) 2026-09-17 17:17:56 -04:00
resources fix(ui): update missing German translations (#6146) 2026-09-20 12:17:57 -04:00
scanner feat(cli): add missing file list and remap subcommands (#5928) 2026-09-12 12:08:25 -04:00
scheduler fix(log): change debug log level to trace to reduce log noise from cron 2026-08-06 00:40:58 -04:00
scripts build(worktree): add script for setting up git worktrees 2026-03-17 21:34:00 -04:00
server fix: apply the per-user library filter to bookmarks, playlists and now-playing (#6179) 2026-09-20 12:37:18 -04:00
tests fix(artwork): only use image files as local artwork sources (#6180) 2026-09-20 13:40:14 -04:00
ui fix(auth): ExtAuth logout redirect on unauthenticated loads, and warning spam from untrusted sources (#6176) 2026-09-19 17:08:49 -04:00
utils fix(artwork): block private and loopback addresses in remote image fetches (#6181) 2026-09-20 20:46:46 -04:00
.dockerignore fix: add music.old to .dockerignore and .gitignore 2026-02-06 07:40:05 -05:00
.git-blame-ignore-revs Move project to Navidrome GitHub organization 2021-02-06 21:47:19 -05:00
.gitignore ci: run the plugins test suite in parallel processes (#6051) 2026-08-30 16:57:40 -04:00
.golangci.yml refactor: replace md5 with xxh3 for faster and more efficient hashing 2026-08-19 09:28:25 -04:00
.nvmrc chore(deps): update all dependencies (#4618) 2025-10-25 17:05:16 -04:00
.octocov.yml ci: exclude tests/ from the coverage report on pull requests too (#6070) 2026-09-01 23:02:15 -04:00
CODE_OF_CONDUCT.md Use Contributor Covenant v2.0 2020-07-21 14:40:21 -04:00
context7.json Add context7.json with URL and public key 2026-04-14 19:19:42 -04:00
CONTRIBUTING.md docs: update commit message format in CONTRIBUTING.md 2026-02-20 11:00:34 -05:00
Dockerfile build(docker): add curl to container image (#6111) (#6116) 2026-09-09 11:38:59 -04:00
go.mod fix(server): return 404 instead of 500 for missing native API resources (#6131) 2026-09-14 22:46:21 -04:00
go.sum fix(server): return 404 instead of 500 for missing native API resources (#6131) 2026-09-14 22:46:21 -04:00
LICENSE Change license to GPLv3 2020-01-22 14:48:38 -05:00
main.go feat(server): implement FTS5-based full-text search (#5079) 2026-02-21 17:52:42 -05:00
Makefile chore(deps): upgrade to Go 1.27 (#5990) 2026-08-30 12:43:15 -04:00
Procfile.dev chore(deps): upgrade to Go 1.24.1 (#3851) 2025-03-17 21:08:10 -04:00
README.md feat(subsonic): add structured sidecar lyrics support with OpenSubsonic v2 karaoke cues and agent layers (#5076) 2026-06-19 12:00:58 -04:00
reflex.conf fix(reflex): exclude .worktrees from the reflex configuration regex 2026-09-07 14:43:18 -04:00

Navidrome logo

Navidrome Music Server  Tweet

Last Release Build Downloads Docker Pulls Dev Chat Subreddit Contributor Covenant Gurubase

Navidrome is an open source web-based music collection server and streamer. It gives you freedom to listen to your music collection from any browser or mobile device. It's like your personal Spotify!

Note: The master branch may be in an unstable or even broken state during development. Please use releases instead of the master branch in order to get a stable set of binaries.

Check out our Live Demo!

Any feedback is welcome! If you need/want a new feature, find a bug or think of any way to improve Navidrome, please file a GitHub issue or join the discussion in our Subreddit. If you want to contribute to the project in any other way (ui/backend dev, translations, themes), please join the chat in our Discord server.

Installation

See instructions on the project's website

Cloud Hosting

PikaPods has partnered with us to offer you an officially supported, cloud-hosted solution. A share of the revenue helps fund the development of Navidrome at no additional cost for you.

PikaPods

Features

  • Handles very large music collections
  • Streams virtually any audio format available
  • Reads and uses all your beautifully curated metadata
  • Great support for compilations (Various Artists albums) and box sets (multi-disc albums)
  • Multi-user, each user has their own play counts, playlists, favourites, etc...
  • Very low resource usage
  • Multi-platform, runs on macOS, Linux and Windows. Docker images are also provided
  • Ready to use binaries for all major platforms, including Raspberry Pi
  • Automatically monitors your library for changes, importing new files and reloading new metadata
  • Supports lyrics from sidecar .ttml, .yaml/.yml Lyricsfile, .elrc, .lrc, .srt, .txt files and embedded TTML, Enhanced LRC, LRC, SRT, and plain-text tags (via lyricspriority)
  • Themeable, modern and responsive Web interface based on Material UI
  • Compatible with all Subsonic/Madsonic/Airsonic clients
  • Transcoding on the fly. Can be set per user/player. Opus encoding is supported
  • Translated to various languages

Translations

Navidrome uses POEditor for translations, and we are always looking for more contributors

Documentation

All documentation can be found in the project's website: https://www.navidrome.org/docs. Here are some useful direct links:

Screenshots