Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rqr2-9jm2-2q9j

Опубликовано: 21 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 6.4

Описание

AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS pinning validation. An authenticated attacker can supply a downloadURL that redirects to an internal address, causing the unpinned retry to follow the redirect and reach internal targets for blind SSRF attacks.

AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS pinning validation. An authenticated attacker can supply a downloadURL that redirects to an internal address, causing the unpinned retry to follow the redirect and reach internal targets for blind SSRF attacks.

EPSS

Процентиль: 8%
0.00186
Низкий

5.3 Medium

CVSS4

6.4 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.4
nvd
20 дней назад

AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS pinning validation. An authenticated attacker can supply a downloadURL that redirects to an internal address, causing the unpinned retry to follow the redirect and reach internal targets for blind SSRF attacks.

EPSS

Процентиль: 8%
0.00186
Низкий

5.3 Medium

CVSS4

6.4 Medium

CVSS3

Дефекты

CWE-918