← All reports

The AVideo open-source video platform has critical security vulnerabilities in versions 29.0 and below that allow for SSRF attacks and DNS TOCTOU vulnerabilities.

CybersecurityTechnologyConflictApr 22, 2026score 0.172 posts · 0 replies across 1 instances
The thread discusses two high-severity vulnerabilities in the AVideo open-source video platform, affecting versions 29.0 and below. These vulnerabilities involve issues with the `isSSRFSafeURL()` function, allowing potential SSRF attacks and DNS TOCTOU vulnerabilities. The posts highlight the need for patches and security improvements.

Claims

The AVideo open-source video platform has critical security vulnerabilities in versions 29.0 and below that allow for SSRF attacks and DNS TOCTOU vulnerabilities.
Parent: CybersecurityEntity: AVideo open-source video platformImpact: negativeDate: Apr 22, 2026Target: The security of the AVideo open-source video platform

Source posts

@[email protected]
🟠 CVE-2026-41055 - High (8.6) WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks proxy adds `isSSRFSafeURL()` validation but leaves DNS TOCTOU vulnerabilities where DNS rebinding between validation and the act... 🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-41055/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
0 boosts · 0 favs · 0 replies · Apr 22, 2026
#cve#vulnerability#infosec#cybersecurity#security#tenda
@[email protected]
🟠 CVE-2026-41060 - High (7.7) WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/functions.php` contains a same-domain shortcircuit (lines 4290-4296) that allows any URL whose hostname matches `webSiteRootURL` t... 🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-41060/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
0 boosts · 0 favs · 0 replies · Apr 22, 2026
#cve#vulnerability#infosec#cybersecurity#security#tenda