GHSA-rqr2-9jm2-2q9jMediumCVSS 6.4
AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery...
🔗 CVE IDs covered (1)
📋 Description
AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS pinning validation. An authenticated attacker can supply a downloadURL that redirects to an internal address, causing the unpinned retry to follow the redirect and reach internal targets for blind SSRF attacks.
🔗 References (5)
- https://github.com/WWBN/AVideo/security/advisories/GHSA-fr98-mjq9-7jmj
- https://nvd.nist.gov/vuln/detail/CVE-2026-64626
- https://github.com/WWBN/AVideo/commit/0dbadbcaaa1b415c7db078a72dc4b26d9fac0485
- https://www.vulncheck.com/advisories/avideo-encoder-downloadurl-ssrf-via-unpinned-retry-fallback
- https://github.com/advisories/GHSA-rqr2-9jm2-2q9j