CVE-2026-34740General(wwbn / avideo)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the EPG (Electronic Program Guide) link feature in AVideo allows authenticated users with upload permissions to store arbitrary URLs that the server fetches on every EPG page visit. The URL is validated only with PHP's FILTER_VALIDATE_URL, which accepts internal network addresses. Although AVideo has a dedicated isSSRFSafeURL() function for preventing SSRF, it is not called in this code path. This results in a stored server-side request forgery vulnerability that can be used to scan internal networks, access cloud metadata services, and interact with internal services. At time of publication, there are no publicly available patches.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-31); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-31: 1Mentions · 2026-04-01: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 103-3104-01
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-311
General1
2026-04-011
Disclosure1
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-34740 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the EPG (Electronic Program Guide) link feature in AVideo allows authenticated users with up… https://www.cve.org/CVERecord?id=CVE-2026-34740

    Post summary

    The post announces a CVE (CVE‑2026‑34740) affecting the EPG link feature of AVideo versions 26.0 and earlier, noting that authenticated users can exploit it, with further details available in the linked CVE record.

    00010125
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-34740 - AVideo: Stored SSRF via Video EPG Link Missing isSSRFSafeURL() Validation Intel Report: https://ift.tt/hXVuGtM

    Post summary

    The post announces a stored SSRF vulnerability (CVE‑2026‑34740) in AVideo’s Video EPG link validation but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000037
    281 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more