Server-Side Request Forgery Vulnerability in AVideo Encoder by WWBN
CVE-2026-64626

5.3MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-64626?

AVideo versions from commit 0dbadbca through to the latest master release exhibit a server-side request forgery (SSRF) vulnerability within the encoder's download-by-URL functionality. This flaw arises from an unpinned retry fallback mechanism that inadequately enforces DNS pinning validation. By exploiting this vulnerability, an authenticated attacker can manipulate the downloadURL parameter to redirect requests to internal network addresses. This capability allows the attacker to leverage blind SSRF attacks, potentially accessing sensitive internal resources.

Affected Version(s)

AVideo 0dbadbcaaa1b415c7db078a72dc4b26d9fac0485

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.