CVE-2026-56342

AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows authenticated administrators to read arbitrary URLs via the statsURL parameter, which lacks isSSRFSafeURL() validation and accepts requests to private IP ranges and cloud metadata endpoints. Attackers can exploit this by crafting requests to internal services, cloud metadata endpoints like 169.254.169.254, and localhost to retrieve sensitive information including IAM credentials, internal service responses, and network configuration details.
Configurations

No configuration.

History

22 Jun 2026, 16:16

Type Values Removed Values Added
References () https://github.com/WWBN/AVideo/security/advisories/GHSA-wxjx-r2j2-96fx - () https://github.com/WWBN/AVideo/security/advisories/GHSA-wxjx-r2j2-96fx -

20 Jun 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-20 19:16

Updated : 2026-06-22 18:36


NVD link : CVE-2026-56342

Mitre link : CVE-2026-56342

CVE.ORG link : CVE-2026-56342


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)