CVE-2026-64626
published 2026-07-20CVE-2026-64626: AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an…
PriorityP334medium6.4CVSS 3.1
AVNACLPRLUINSCCLILAN
EPSS
0.19%
8.5th percentile
AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS pinning validation. An authenticated attacker can supply a downloadURL that redirects to an internal address, causing the unpinned retry to follow the redirect and reach internal targets for blind SSRF attacks.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wwbn | avideo | — | — |
CVSS provenance
nvdv3.16.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WWBN AVideo Encoder downloadURL server-side request forgery
vuldb·2026-07-21·CVSS 6.4
CVE-2026-64626 [MEDIUM] WWBN AVideo Encoder downloadURL server-side request forgery
A vulnerability identified as critical has been detected in WWBN AVideo. This affects an unknown function of the component Encoder. The manipulation of the argument downloadURL leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-64626. Remote exploitation of the attack is possible. No exploit is available.
GHSA
AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS p
ghsa_unreviewed·2026-07-21
CVE-2026-64626 [MEDIUM] CWE-918 AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS p
AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS pinning validation. An authenticated attacker can supply a downloadURL that redirects to an internal address, causing the unpinned retry to follow the redirect and reach internal targets for blind SSRF attacks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/WWBN/AVideo/commit/0dbadbcaaa1b415c7db078a72dc4b26d9fac0485https://github.com/WWBN/AVideo/security/advisories/GHSA-fr98-mjq9-7jmjhttps://www.vulncheck.com/advisories/avideo-encoder-downloadurl-ssrf-via-unpinned-retry-fallbackhttps://github.com/WWBN/AVideo/security/advisories/GHSA-fr98-mjq9-7jmj
2026-07-20
Published