Allocation of Resources Without Limits or Throttling in AVideo - CVE-2026-33483

 

Allocation of Resources Without Limits or Throttling in AVideo - CVE-2026-33483

Published: April 8, 2026


Vulnerability identifier: #VU125457
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33483
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the objects/aVideoEncoderChunk.json.php endpoint when handling arbitrary POST data. A remote attacker can send specially crafted requests with large request bodies to cause a denial of service.

The endpoint is accessible without authentication, created temporary files persist without cleanup, and the response discloses the full temporary file path.


Affected software

AVideo

How to mitigate CVE-2026-33483

Install security update from vendor's website.

AVideo - update to 29.0

External References

Related Security Bulletins