← Zuruck zu CVEs
CVE-2026-41055
HIGH8.6
Beschreibung
WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks proxy adds `isSSRFSafeURL()` validation but leaves DNS TOCTOU vulnerabilities where DNS rebinding between validation and the actual HTTP request redirects traffic to internal endpoints. Commit 8d8fc0cadb425835b4861036d589abcea4d78ee8 contains an updated fix.
CVE Details
CVSS v3.1 Bewertung8.6
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht4/21/2026
Zuletzt geandert4/23/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
wwbn:avideo
Schwachen (CWE)
CWE-918
Referenzen
https://github.com/WWBN/AVideo/commit/0e56382921fc71e64829cd1ec35f04e338c70917(security-advisories@github.com)
https://github.com/WWBN/AVideo/commit/8d8fc0cadb425835b4861036d589abcea4d78ee8(security-advisories@github.com)
https://github.com/WWBN/AVideo/security/advisories/GHSA-793q-xgj6-7frp(security-advisories@github.com)
https://github.com/WWBN/AVideo/security/advisories/GHSA-9x67-f2v7-63rw(security-advisories@github.com)
https://github.com/WWBN/AVideo/security/advisories/GHSA-793q-xgj6-7frp(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.