
🔴 WWBN AVideo, SSRF, #CVE-2026-33237 (Critical) https://dailycve.com/wwbn-avideo-ssrf-cve-2026-33237-critical/
Post summary
A brief alert noting the discovery of a critical SSRF vulnerability, CVE-2026-33237, in WWBN AVideo.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/Scheduler/Scheduler.php` calls `url_get_contents()` with an admin-configurable `callbackURL` that is validated only by `isValidURL()` (URL format check). Unlike other AVideo endpoints that were recently patched for SSRF (GHSA-9x67-f2v7-63rw, GHSA-h39h-7cvg-q7j6), the Scheduler's callback URL is never passed through `isSSRFSafeURL()`, which blocks requests to RFC-1918 private addresses, loopback, and cloud metadata endpoints. An admin can configure a scheduled task with an internal network `callbackURL` to perform SSRF against cloud infrastructure metadata services or internal APIs not otherwise reachable from the internet. Version 26.0 contains a patch for the issue.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-03-21 | 2 | Disclosure2 |
| 2026-03-24 | 1 | General1 |

🔴 WWBN AVideo, SSRF, #CVE-2026-33237 (Critical) https://dailycve.com/wwbn-avideo-ssrf-cve-2026-33237-critical/
Post summary
A brief alert noting the discovery of a critical SSRF vulnerability, CVE-2026-33237, in WWBN AVideo.

CVE-2026-33237 WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/Scheduler/Scheduler.php` calls `url_get_conten… https://www.cve.org/CVERecord?id=CVE-2026-33237
Post summary
The text announces CVE‑2026‑33237 affecting the Scheduler plugin in WWBN AVideo before version 26.0, with no additional details on exploitation or mitigation.

🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33237 - AVideo has SSRF in Scheduler Plugin via callbackURL Missing `isSSRFSafeURL()` Validation Intel Report: https://ift.tt/deHP6iX
Post summary
A new SSRF vulnerability (CVE-2026-33237) has been identified in AVideo's Scheduler Plugin due to missing callbackURL validation, with an intel report provided.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | wwbn | avideo | - | - | - |