Description
A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this vulnerability is the function stream of the file public/stream.php. The manipulation of the argument url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. Commit 6ffe823 'better security for public/stream.php' only added CURLOPT_PROTOCOLS http/https restriction and MAXREDIRS cap, does not restrict destination host. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Server‑side request forgery (SSRF)
Action: Apply Patch
AI Analysis

Impact

The vulnerability exists in the stream function of public/stream.php and is triggered by manipulating the url parameter. Exploitation allows an attacker to cause the server to send arbitrary HTTP or HTTPS requests to any destination, potentially exposing internal resources or enabling data exfiltration. The weakness is a classic SSRF flaw, classified as CWE‑918.

Affected Systems

The affected product is athlon1600 youtube‑downloader; releases up to version 4.0.1 are vulnerable. No patch is presently available from the vendor, and the contact was not responded to.

Risk and Exploitability

The CVSS score is 6.9, indicating a medium severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited yet possible industrial impact. The attack vector is remote, as the exploitation is performed through a crafted URL request to the server. An attacker could leverage this to reach internal hosts or retrieve sensitive data.

Generated by OpenCVE AI on September 28, 2026 at 04:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade athlon1600 youtube‑downloader to a version that fully patches the stream.php SSRF flaw or applies an official vendor fix.
  • If upgrading is not possible, restrict outbound connections from the application by using network firewall rules or host‑based access control to block requests to private networks or disallowed domains.
  • Implement server‑side validation that limits URL protocols and hostnames to an approved whitelist before passing them to cURL, thereby preventing unauthorized remote requests.

Generated by OpenCVE AI on September 28, 2026 at 04:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this vulnerability is the function stream of the file public/stream.php. The manipulation of the argument url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. Commit 6ffe823 'better security for public/stream.php' only added CURLOPT_PROTOCOLS http/https restriction and MAXREDIRS cap, does not restrict destination host. The vendor was contacted early about this disclosure but did not respond in any way.
Title athlon1600 youtube-downloader stream.php stream server-side request forgery
First Time appeared Athlon1600
Athlon1600 youtube-downloader
Weaknesses CWE-918
CPEs cpe:2.3:a:athlon1600:youtube-downloader:*:*:*:*:*:*:*:*
Vendors & Products Athlon1600
Athlon1600 youtube-downloader
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Athlon1600 Youtube-downloader
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T02:45:10.743Z

Reserved: 2026-09-27T08:49:53.864Z

Link: CVE-2026-100901

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T03:16:38.803

Modified: 2026-09-28T03:16:38.803

Link: CVE-2026-100901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T04:30:18Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)