CVE-2026-33766 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

WWBN AVideo is an open source video platform. In versions up to and including 26.0, `isSSRFSafeURL()` validates URLs against private/reserved IP ranges before f…
Medium CVSS: 5.3

CVE-2026-33766

WWBN AVideo is an open source video platform. In versions up to and including 26.0, `isSSRFSafeURL()` validates URLs against private/reserved IP ranges before fetching, but `url_get_contents()` follows HTTP redirects without re-validating the redirect target. An attacker can bypass SSRF protection by redirecting from a public URL to an internal target. Commit 8b7e9dad359d5fac69e0cbbb370250e0b284bc12 contains a patch.
Vendor
Wwbn
Product
Avideo
CWE
CWE-918
Yayın Tarihi
2026-03-27 15:16:58
Güncelleme
2026-03-31 18:48:32
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar