Server-Side Request Forgery Vulnerability in AVideo Encoder by WWBN
CVE-2026-64626
5.3MEDIUM
What is CVE-2026-64626?
AVideo versions from commit 0dbadbca through to the latest master release exhibit a server-side request forgery (SSRF) vulnerability within the encoder's download-by-URL functionality. This flaw arises from an unpinned retry fallback mechanism that inadequately enforces DNS pinning validation. By exploiting this vulnerability, an authenticated attacker can manipulate the downloadURL parameter to redirect requests to internal network addresses. This capability allows the attacker to leverage blind SSRF attacks, potentially accessing sensitive internal resources.
Affected Version(s)
AVideo 0dbadbcaaa1b415c7db078a72dc4b26d9fac0485
