CVE-2026-56285

Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute valid HMACs for arbitrary URLs. Attackers can retrieve HTTP responses from any host reachable by the server, including cloud metadata services and internal network resources.
Configurations

No configuration.

History

29 Jun 2026, 20:17

Type Values Removed Values Added
References () https://github.com/zedeus/nitter/issues/1411 - () https://github.com/zedeus/nitter/issues/1411 -

29 Jun 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-29 18:16

Updated : 2026-07-14 22:17


NVD link : CVE-2026-56285

Mitre link : CVE-2026-56285

CVE.ORG link : CVE-2026-56285


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)

CWE-1188

Insecure Default Initialization of Resource