Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4m2j-2x3w-gg93

Опубликовано: 29 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.7
CVSS3: 8.6

Описание

Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute valid HMACs for arbitrary URLs. Attackers can retrieve HTTP responses from any host reachable by the server, including cloud metadata services and internal network resources.

Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute valid HMACs for arbitrary URLs. Attackers can retrieve HTTP responses from any host reachable by the server, including cloud metadata services and internal network resources.

EPSS

Процентиль: 40%
0.00481
Низкий

7.7 High

CVSS4

8.6 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.6
nvd
2 месяца назад

Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute valid HMACs for arbitrary URLs. Attackers can retrieve HTTP responses from any host reachable by the server, including cloud metadata services and internal network resources.

EPSS

Процентиль: 40%
0.00481
Низкий

7.7 High

CVSS4

8.6 High

CVSS3

Дефекты

CWE-918