9.3 CVE-2026-33502
Enriched by CISA Patch Exploit
WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `plugin/Live/test.php` allows any remote user to make the AVideo server send HTTP requests to arbitrary URLs. This can be used to probe localhost/internal services and, when reachable, access internal HTTP resources or cloud metadata endpoints. Commit 1e6cf03e93b5a5318204b010ea28440b0d9a5ab3 contains a patch.
https://nvd.nist.gov/vuln/detail/CVE-2026-33502
Categories
CWE-918 : Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. Cross Site Port Attack Server-Side Request Forgery Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.) SSRF in LLM application development framework because the URL retriever allows connections to local addresses using a crafted Location header Chain: LLM integration framework has prompt injection(CWE-1427) that allows an attacker to force the service to retrievedata from an arbitrary URL, essentially providing SSRF (CWE-918) andpotentially injecting content into downstream tasks. Server Side Request Forgery (SSRF) in mail server, as exploited in the wild per CISA KEV. Server Side Request Forgery in cloud platform, as exploited in the wild per CISA KEV. Chain: incorrect validation of intended decimal-based IP address format (CWE-1286) enables parsing of octal or hexadecimal formats (CWE-1389), allowing bypass of an SSRF protection mechanism (CWE-918). Web server allows attackers to request a URL from another server, including other ports, which allows proxied scanning. CGI script accepts and retrieves incoming URLs. Web-based mail program allows internal network scanning using a modified POP3 port number. URL-downloading library automatically follows redirects to file:// and scp:// URLs
References
134c704f-9b21-4f2e-91b3-4a467353bcc0 Exploit
| https://github.com/WWBN/AVideo/security/advisories/GHSA-3fpm-8rjr-v5mc Exploit Mitigation Vendor Advisory |
security-advisories@github.com Patch Exploit
| https://github.com/WWBN/AVideo/commit/1e6cf03e93b5a5318204b010ea28440b0d9a5ab3 Patch |
| https://github.com/WWBN/AVideo/security/advisories/GHSA-3fpm-8rjr-v5mc Exploit Mitigation Vendor Advisory |
AFFECTED (from MITRE)
| Vendor | Product | Versions |
|---|---|---|
| WWBN | AVideo | |
| © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. | ||
CPE
| cpe | start | end |
|---|---|---|
| Configuration 1 | ||
| cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* | <= 26.0 | |
REMEDIATION
Patch
| Url |
|---|
| https://github.com/WWBN/AVideo/commit/1e6cf03e93b5a5318204b010ea28440b0d9a5ab3 |
EXPLOITS
Exploit-db.com
| id | description | date | |
|---|---|---|---|
| No known exploits | |||
POC Github
| Url |
|---|
| No known exploits |
Other Nist (github, ...)
| Url |
|---|
| https://github.com/WWBN/AVideo/security/advisories/GHSA-3fpm-8rjr-v5mc |
| https://github.com/WWBN/AVideo/security/advisories/GHSA-3fpm-8rjr-v5mc |
CAPEC
Common Attack Pattern Enumerations and Classifications
| id | description | severity |
|---|---|---|
| 664 | Server Side Request Forgery |
High |
Cybersecurity needs ?
Strengthen software security from the outset with our DevSecOps expertise
Integrate security right from the start of the software development cycle for more robust applications and greater customer confidence.
Our team of DevSecOps experts can help you secure your APIs, data pipelines, CI/CD chains, Docker containers and Kubernetes deployments.
