Blind Server-Side Request Forgery in AVideo by WWBN
CVE-2026-91967
5.3MEDIUM
What is CVE-2026-91967?
AVideo versions prior to 29.0 contain a vulnerability that allows authenticated users with upload permissions to exploit the getHeaderContentTypeFromURL function. This flaw permits the issuing of get_headers() calls, which are only partially safeguarded by format validation. By storing malicious URLs as video links, attackers can trigger the vulnerable function during the rendering of video watch pages, enabling internal host probing through content-type oracles and timing-based detection mechanisms.
Affected Version(s)
AVideo 0 <= 29.0
