
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27732 is an authenticated Server-Side Request Forgery (SSRF) vulnerability in WWBN AVideo, an open source video platform. The flaw exists in the aVideoEncoder.json.php API endpoint, which accepts a downloadURL parameter and fetches the referenced resource server-side without proper validation or an allow-list. All AVideo versions prior to 22.0 are affected. The vulnerability was responsibly disclosed by researcher Arkadiusz Marta, published to the GitHub Advisory Database on February 23, 2026, and assigned a CVSS v3.1 score of 8.1 (High) and a CVSS v4.0 score of 8.6 (High) (GitHub Advisory, Github Advisory).
The root cause is classified as CWE-918 (Server-Side Request Forgery), where the downloadVideoFromDownloadURL() function in objects/aVideoEncoder.json.php directly passes the attacker-supplied downloadURL parameter to a server-side HTTP fetch function (url_get_contents()) without validating the destination against an allow-list or blocking internal/private address ranges (GitHub Advisory). The attack is network-based, requires low privileges (a valid authenticated session), and no user interaction. The fix introduced an isSSRFSafeURL() function that enforces scheme restrictions (http/https only), blocks localhost and loopback addresses, private IPv4 ranges (10.x.x.x, 172.16–31.x.x, 192.168.x.x), link-local addresses (169.254.x.x including cloud metadata endpoints), and IPv6 private/local addresses, and was applied across multiple files including aVideoEncoderReceiveImage.json.php and plugin/AI/receiveAsync.json.php (AVideo Commit).
Successful exploitation allows an authenticated attacker to make the AVideo server issue HTTP requests to arbitrary URLs, including internal network services, cloud metadata endpoints (e.g., http://169.254.169.254/), and other infrastructure not directly accessible from the internet. This can result in high confidentiality and integrity impact — sensitive data such as internal API responses, credentials, or cloud instance metadata can be retrieved and potentially used for lateral movement or further compromise of the deployment environment. Availability is not directly impacted by this vulnerability (Github Advisory, GitHub Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (Feedly). The EPSS score is approximately 0.04% (13th percentile), indicating a low near-term probability of exploitation (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Exploitation requires a valid authenticated account on the AVideo instance, which limits the attack surface compared to unauthenticated vulnerabilities.
aVideoEncoder.json.php API endpoint on the target server (e.g., https://target.example.com/objects/aVideoEncoder.json.php).downloadURL parameter pointing to an internal resource, such as the cloud metadata service:POST /objects/aVideoEncoder.json.php HTTP/1.1
Host: target.example.com
Cookie: <authenticated_session_cookie>
downloadURL=http://169.254.169.254/latest/meta-data/aVideoEncoder log entries) showing blocked or attempted requests to internal/private URLs if SSRF protection is active; web server access logs showing authenticated POST requests to /objects/aVideoEncoder.json.php with unusual downloadURL parameter values pointing to internal addresses.The vulnerability is fixed in AVideo version 22.0, which introduces the isSSRFSafeURL() validation function applied to all URL-fetching operations across affected files (AVideo Release 22.0, AVideo Commit). Administrators should upgrade to version 22.0 or later as the primary remediation. For systems that cannot be immediately patched, implement network-level egress filtering to block the AVideo server from making outbound connections to internal IP ranges and cloud metadata endpoints, and restrict access to the aVideoEncoder.json.php endpoint to trusted users only (Feedly).
The vulnerability received routine coverage across CVE tracking platforms and security aggregators shortly after disclosure. Social media posts on Bluesky and Mastodon noted the advisory, and it was included in at least one cybersecurity news brief (Straylight Sentinel). No significant vendor statements beyond the official GitHub security advisory, nor notable independent researcher commentary, have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."