CVE-2026-33480Disclosure(wwbn / avideo)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch wwbn avideo systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeURL()` function in AVideo can be bypassed using IPv4-mapped IPv6 addresses (`::ffff:x.x.x.x`). The unauthenticated `plugin/LiveLinks/proxy.php` endpoint uses this function to validate URLs before fetching them with curl, but the IPv4-mapped IPv6 prefix passes all checks, allowing an attacker to access cloud metadata services, internal networks, and localhost services. Commit 75ce8a579a58c9d4c7aafe453fbced002cb8f373 contains a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-23); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-23: 3Mentions · 2026-04-07: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-23: 3Technical Details · 2026-04-07: 103-2304-07
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-233
Disclosure2Patch1
2026-04-071
Disclosure1
Full discourse4 posts
  • Firmis Labs@FirmisLabs
    Disclosure

    CVE-2026-33480 · NIST 8.6/10 https://nvd.nist.gov/vuln/detail/CVE-2026-33480

    Post summary

    The tweet lists CVE-2026-33480 with an NIST CVSS severity of 8.6/10, but contains no evidence of exploitation, patches, or mitigation details.

    1000022
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33480 Server-Side Request Forgery Bypass in WWBN AVideo via IPv4-Mapped IPv6 Addresses https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33480

    Post summary

    CVE‑2026‑33480 is disclosed as a Server‑Side Request Forgery bypass in WWBN AVideo that exploits IPv4‑mapped IPv6 addresses. No PoC, exploit code, active exploitation, or patch information is provided in the text.

    0000072
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33480: HIGH] AVideo platform versions <=26.0 vulnerable to bypassing cyber security measures using IPv4-mapped IPv6 addresses. Patch available in commit 75ce8a579a58c9d4c7aafe453fbced002cb8f373.#cve,CVE-2026-33480,#cybersecurity https://cvefind.com/CVE-2026-33480

    Post summary

    CVE-2026-33480 affects AVideo platform versions <=26.0, allowing security bypass via IPv4-mapped IPv6 addresses; a patch is available in a specified commit.

    0000062
    606 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33480 - High WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeURL()` function in AVideo can be bypassed using IPv4-mapped IPv6 addresses (`::ffff:x.x.x.x`... https://www.thehackerwire.com/vulnerability/CVE-2026-33480/ https://t.co/YpnXZlsxpn

    Post summary

    WWBN AVideo version 26.0 and earlier contain a vulnerability where the `isSSRFSafeURL()` function can be bypassed with IPv4‑mapped IPv6 addresses; the post details the technical flaw but does not mention exploitation or remediation.

    0000057
    144 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more