The AVideo open-source video platform has critical security vulnerabilities in versions 29.0 and below that allow for SSRF attacks and DNS TOCTOU vulnerabilities.
Claims
The AVideo open-source video platform has critical security vulnerabilities in versions 29.0 and below that allow for SSRF attacks and DNS TOCTOU vulnerabilities.
Parent: CybersecurityEntity: AVideo open-source video platformImpact: negativeDate: Apr 22, 2026Target: The security of the AVideo open-source video platform
Source posts
🟠 CVE-2026-41055 - High (8.6)
WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks proxy adds `isSSRFSafeURL()` validation but leaves DNS TOCTOU vulnerabilities where DNS rebinding between validation and the act...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-41055/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
0 boosts · 0 favs · 0 replies · Apr 22, 2026
#cve#vulnerability#infosec#cybersecurity#security#tenda
🟠 CVE-2026-41060 - High (7.7)
WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/functions.php` contains a same-domain shortcircuit (lines 4290-4296) that allows any URL whose hostname matches `webSiteRootURL` t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-41060/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
0 boosts · 0 favs · 0 replies · Apr 22, 2026
#cve#vulnerability#infosec#cybersecurity#security#tenda