#VU125457 Allocation of Resources Without Limits or Throttling in AVideo - CVE-2026-33483

 

#VU125457 Allocation of Resources Without Limits or Throttling in AVideo - CVE-2026-33483

Published: April 8, 2026


Vulnerability identifier: #VU125457
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-33483
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
AVideo
Software vendor:
World Wide Broadcast Network

Description

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the objects/aVideoEncoderChunk.json.php endpoint when handling arbitrary POST data. A remote attacker can send specially crafted requests with large request bodies to cause a denial of service.

The endpoint is accessible without authentication, created temporary files persist without cleanup, and the response discloses the full temporary file path.


Remediation

Install security update from vendor's website.

External links