Server-Side Request Forgery Vulnerability in Frigate Network Video Recorder
CVE-2026-33126

5MEDIUM

Key Information:

Status
Vendor
CVE Published:
20 March 2026

What is CVE-2026-33126?

Frigate, a network video recorder featuring real-time local object detection for IP cameras, has a security vulnerability in its /ffprobe endpoint. Prior to version 0.16.3, this endpoint allowed arbitrary user-controlled URLs without adequate validation. This oversight opens the door for Server-Side Request Forgery (SSRF) attacks, enabling malicious actors to make unauthorized HTTP requests to internal network resources, access cloud metadata services, or conduct port scanning activities from the Frigate server. Users are urged to patch their systems by upgrading to version 0.16.3 to safeguard against these potential threats.

Affected Version(s)

frigate < 0.16.3

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.