Description
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted an attacker-controlled restreamerURL and later fetched that stored URL server-side, enabling stored SSRF for authenticated streamers. The vulnerable flow allowed a low-privilege user with streaming permission to store an arbitrary callback URL and trigger server-side requests to loopback or internal HTTP services through the restream log feature.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q4x6-6mm2-crg9 | WWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal services |
References
History
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted an attacker-controlled restreamerURL and later fetched that stored URL server-side, enabling stored SSRF for authenticated streamers. The vulnerable flow allowed a low-privilege user with streaming permission to store an arbitrary callback URL and trigger server-side requests to loopback or internal HTTP services through the restream log feature. | |
| Title | WWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal services | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T20:02:21.185Z
Reserved: 2026-04-06T21:29:17.350Z
Link: CVE-2026-39368
Updated: 2026-04-07T20:02:17.750Z
Status : Received
Published: 2026-04-07T20:16:30.877
Modified: 2026-04-07T20:16:30.877
Link: CVE-2026-39368
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA