#VU125511 Server-Side Request Forgery (SSRF) in AVideo - CVE-2026-39368
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote user to disclose sensitive information from internal services.
The vulnerability exists due to server-side request forgery (SSRF) in the Live restream log callback flow when processing a stored attacker-controlled restreamerURL. A remote user can store a crafted callback URL and trigger server-side requests to internal or loopback services to disclose sensitive information from internal services.
Exploitation requires streaming permission, and the server-fetched response can be returned through normal application endpoints.