Server-Side Request Forgery Vulnerability in AVideo by WWBN
CVE-2026-81678

6.9MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-81678?

AVideo versions prior to 24.0 are susceptible to a server-side request forgery (SSRF) vulnerability in the isSSRFSafeURL function. This flaw arises from the inability to correctly handle embedded IPv4 addresses formatted as NAT64, 6to4, and Teredo IPv6 transition addresses. Unauthenticated attackers can exploit this vulnerability through the LiveLinks proxy endpoint, effectively bypassing SSRF protections. Such exploitation allows remote access to internal services and sensitive cloud metadata endpoints by encoding private IPv4 targets in transition address formats.

Affected Version(s)

AVideo 0 < 24.0

AVideo 24.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.