Server-Side Request Forgery Vulnerability in HummerRisk Video Download Handler
CVE-2026-6220
Key Information:
- Vendor
HummerRisk
- Status
- Vendor
- CVE Published:
- 13 April 2026
Badges
What is CVE-2026-6220?
In versions of HummerRisk up to 1.5.0, a server-side request forgery (SSRF) vulnerability was discovered in the ServerService.addServer function within the ServerService.java file. This security flaw enables remote exploitation by manipulating the streamIp argument during server operations. As a result, attackers can potentially send unauthorized requests to internal systems or other external services. The vulnerability is publicly documented, and the vendor has been unresponsive to inquiries regarding its resolution, necessitating immediate attention from users to mitigate risks.
Affected Version(s)
HummerRisk 1.0
HummerRisk 1.1
HummerRisk 1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
