Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute valid HMACs for arbitrary URLs. Attackers can retrieve HTTP responses from any host reachable by the server, including cloud metadata services and internal network resources.
References
Configurations
No configuration.
History
29 Jun 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/zedeus/nitter/issues/1411 - |
29 Jun 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-29 18:16
Updated : 2026-07-14 22:17
NVD link : CVE-2026-56285
Mitre link : CVE-2026-56285
CVE.ORG link : CVE-2026-56285
JSON object : View
Products Affected
No product.
