
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33483 is an unauthenticated disk space exhaustion vulnerability in WWBN AVideo, affecting all versions up to and including 26.0. The flaw resides in the objects/aVideoEncoderChunk.json.php endpoint, which accepts arbitrary POST data and writes it to persistent temp files in /tmp/ with no authentication, no size limits, and no cleanup mechanism. Disclosed on March 20, 2026, via a GitHub Security Advisory, it carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).
The root cause is CWE-770 (Allocation of Resources Without Limits or Throttling): the aVideoEncoderChunk.json.php script operates entirely outside the AVideo framework with no require_once, no session handling, and no calls to authentication functions such as useVideoHashOrLogin() or canUpload(). It reads raw POST body via php://input in 1MB chunks and writes them to a temp file created with tempnam(sys_get_temp_dir(), 'YTPChunk_'), with the effective upload limit being PHP's post_max_size (AVideo's .htaccess references a commented-out 4GB setting). Compounding the issue, the endpoint sets Access-Control-Allow-Origin: *, enabling cross-origin exploitation from any malicious webpage, and the response JSON discloses the full filesystem path of the created temp file (e.g., {"file":"/tmp/YTPChunk_abc123","filesize":104857600}). The endpoint is publicly routed via .htaccess rewrite at /aVideoEncoderChunk.json (GitHub Advisory).
Successful exploitation causes cascading denial-of-service: filling /tmp/ breaks PHP session handling, causes MySQL temporary table operations to fail, and crashes system services relying on tmpfs — potentially taking down the entire server, not just the AVideo application. Because created files are never cleaned up automatically, even a brief attack has persistent impact requiring manual administrator intervention. Additionally, the endpoint leaks the server's filesystem directory structure via the temp file path returned in the JSON response (GitHub Advisory).
A proof-of-concept exploit consisting of explicit curl commands and bash scripts is publicly available in the official security advisory, rated high confidence by Feedly threat intelligence. The PoC demonstrates writing 100MB files and running 10 concurrent requests (totaling 1GB) to exhaust disk space. No authentication is required, and the CORS wildcard header enables distributed exploitation through visitors' browsers on any malicious website, effectively bypassing IP-based rate limiting. The EPSS score is approximately 0.395% (0.61% per the GitHub Advisory), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (GitHub Advisory).
/aVideoEncoderChunk.json endpoint.curl -s -X POST https://target/aVideoEncoderChunk.json \
-H 'Content-Type: application/octet-stream' \
--data-binary 'test'
# Expected: {"file":"/tmp/YTPChunk_XXXXXX","filesize":4}dd piped to curl to write 100MB files per request:dd if=/dev/zero bs=1M count=100 2>/dev/null | \
curl -s -X POST https://target/aVideoEncoderChunk.json \
-H 'Content-Type: application/octet-stream' \
--data-binary @-/tmp/:for i in $(seq 1 10); do
dd if=/dev/zero bs=1M count=100 2>/dev/null | \
curl -s -X POST https://target/aVideoEncoderChunk.json \
-H 'Content-Type: application/octet-stream' \
--data-binary @- &
done
wait/tmp/ is full, PHP session handling, MySQL temp tables, and tmpfs-dependent services fail, taking down the server. Files persist indefinitely until manual cleanup (GitHub Advisory)./aVideoEncoderChunk.json (or the underlying objects/aVideoEncoderChunk.json.php) from multiple source IPs; large Content-Length values in POST requests to this endpoint; cross-origin requests from unexpected referrer domains./tmp/YTPChunk_*; unusually high /tmp/ directory disk usage; files in /tmp/ with YTPChunk_ prefix that are not being consumed or deleted./aVideoEncoderChunk.json with large payloads; PHP error logs showing disk-full errors or failed tempnam() calls; MySQL error logs indicating failure to create temporary tables due to disk space exhaustion./tmp/; PHP session creation failures; service crashes for applications relying on tmpfs (GitHub Advisory).The official fix is commit 33d1bae6c731ef1682fcdc47b428313be073a5d1, which rewrites objects/aVideoEncoderChunk.json.php to enforce authentication checks, enforce a configurable upload size limit (e.g., 200MB), abort and delete temp files if the stream exceeds the limit, and avoid exposing the full filesystem path in the response (AVideo Commit). Administrators should update AVideo to a version beyond 26.0 that includes this patch. As interim workarounds: block or restrict access to /aVideoEncoderChunk.json at the web server or firewall level; implement network-level rate limiting on POST requests to this endpoint; add a cron job to periodically remove /tmp/YTPChunk_* files older than a configurable threshold (e.g., 1 hour); and replace the CORS wildcard header with a restrictive Access-Control-Allow-Origin policy (GitHub Advisory).
The vulnerability was reported by a researcher identified as "offset" and published by AVideo maintainer DanielnetoDotCom on March 20, 2026. Coverage appeared on security aggregators including VulDB, CVEFeed, and Mastodon security feeds shortly after disclosure. A dedicated write-up was published at infinitsec.net highlighting the unauthenticated disk exhaustion angle (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."