CVE-2026-41055
CVE-2026-41055
8.6
HighPublished:
Last updated:
Source:security-advisories@github.com
Analyzed
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- None
- Availability
- None
Description
WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks proxy adds `isSSRFSafeURL()` validation but leaves DNS TOCTOU vulnerabilities where DNS rebinding between validation and the actual HTTP request redirects traffic to internal endpoints. Commit 8d8fc0cadb425835b4861036d589abcea4d78ee8 contains an updated fix.
References
security-advisories@github.com
https://github.com/WWBN/AVideo/commit/0e56382921fc71e64829cd1ec35f04e338c70917security-advisories@github.com
https://github.com/WWBN/AVideo/commit/8d8fc0cadb425835b4861036d589abcea4d78ee8security-advisories@github.com
https://github.com/WWBN/AVideo/security/advisories/GHSA-793q-xgj6-7frpsecurity-advisories@github.com
https://github.com/WWBN/AVideo/security/advisories/GHSA-9x67-f2v7-63rw134c704f-9b21-4f2e-91b3-4a467353bcc0
https://github.com/WWBN/AVideo/security/advisories/GHSA-793q-xgj6-7frp