Server-Side Request Forgery (SSRF) in AVideo - CVE-2026-33480

 

Server-Side Request Forgery (SSRF) in AVideo - CVE-2026-33480

Published: April 8, 2026


Vulnerability identifier: #VU125459
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2026-33480
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information from internal services, localhost services, and cloud metadata endpoints.

The vulnerability exists due to server-side request forgery in plugin/LiveLinks/proxy.php and isSSRFSafeURL() when handling user-supplied URLs containing IPv4-mapped IPv6 addresses. A remote attacker can send a specially crafted request to disclose sensitive information from internal services, localhost services, and cloud metadata endpoints.

The vulnerable endpoint is unauthenticated, and the fetched response content is echoed back to the requester.


Affected software

AVideo

How to mitigate CVE-2026-33480

Install security update from vendor's website.

AVideo - update to 29.0

External References

Related Security Bulletins