CVE-2026-64626: Server-Side Request Forgery (SSRF) in WWBN AVideo
AVideo contains a server-side request forgery (SSRF) vulnerability in the encoder download-by-URL feature. The issue arises from an unpinned retry fallback mechanism that bypasses DNS pinning validation. An authenticated attacker can exploit this by supplying a download URL that redirects to internal network addresses, enabling blind SSRF attacks. The vulnerability affects versions from commit 0dbadbca through the latest master as of the report date. No official patch or remediation guidance has been provided yet. The CVSS 4.0 base score rates this vulnerability as medium severity.
AI Analysis
Technical Summary
CVE-2026-64626 describes an SSRF vulnerability in WWBN AVideo's encoder download-by-URL flow. The root cause is an unpinned retry fallback that circumvents DNS pinning validation, allowing an authenticated attacker to provide a download URL that redirects to internal IP addresses. This leads to blind SSRF attacks against internal targets. The vulnerability affects all versions from commit 0dbadbca through the latest master branch at the time of disclosure. No vendor advisory or patch information is currently available.
Potential Impact
An authenticated attacker can exploit this vulnerability to cause the server to make HTTP requests to internal network resources that are otherwise inaccessible externally. This may lead to unauthorized internal network reconnaissance or interaction with internal services. The impact is limited by the requirement for authentication and the medium severity rating.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict authenticated user capabilities to supply arbitrary download URLs if possible, and monitor for unusual internal request activity related to the encoder download feature.
CVE-2026-64626: Server-Side Request Forgery (SSRF) in WWBN AVideo
Description
AVideo contains a server-side request forgery (SSRF) vulnerability in the encoder download-by-URL feature. The issue arises from an unpinned retry fallback mechanism that bypasses DNS pinning validation. An authenticated attacker can exploit this by supplying a download URL that redirects to internal network addresses, enabling blind SSRF attacks. The vulnerability affects versions from commit 0dbadbca through the latest master as of the report date. No official patch or remediation guidance has been provided yet. The CVSS 4.0 base score rates this vulnerability as medium severity.
CVSS v4.0
Score 5.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-64626 describes an SSRF vulnerability in WWBN AVideo's encoder download-by-URL flow. The root cause is an unpinned retry fallback that circumvents DNS pinning validation, allowing an authenticated attacker to provide a download URL that redirects to internal IP addresses. This leads to blind SSRF attacks against internal targets. The vulnerability affects all versions from commit 0dbadbca through the latest master branch at the time of disclosure. No vendor advisory or patch information is currently available.
Potential Impact
An authenticated attacker can exploit this vulnerability to cause the server to make HTTP requests to internal network resources that are otherwise inaccessible externally. This may lead to unauthorized internal network reconnaissance or interaction with internal services. The impact is limited by the requirement for authentication and the medium severity rating.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict authenticated user capabilities to supply arbitrary download URLs if possible, and monitor for unusual internal request activity related to the encoder download feature.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-20T11:58:54.524Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5e9d432a4a8d5989d50705
Added to database: 07/20/2026, 22:12:19 UTC
Last enriched: 07/20/2026, 22:27:01 UTC
Last updated: 07/21/2026, 09:12:44 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.