CVE-2026-33502: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33502 is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in WWBN AVideo, an open-source video platform. The flaw exists in the plugin/Live/test.php endpoint and affects all versions up to and including 26.0. It was disclosed on March 20, 2026, via a GitHub Security Advisory, with NVD publication on March 23, 2026. The vulnerability carries a CVSS v3.1 base score of 8.2 (High) per Feedly/NVD, though the GitHub advisory assigns a score of 9.3 (Critical) with a scope-changed vector (GitHub Advisory).

Technical details

The root cause is CWE-918 (Server-Side Request Forgery): the plugin/Live/test.php endpoint accepts a user-supplied statsURL parameter via $_REQUEST['statsURL'] and performs only a minimal check — verifying the value is non-empty, not php://input, and starts with http — before passing it directly to url_get_contents(), which internally calls file_get_contents() when allow_url_fopen is enabled. There is no authentication check, no allowlist of trusted URLs, no SSRF-safe validation (e.g., blocking RFC1918, loopback, or cloud metadata ranges), and the raw upstream response or error output is reflected back to the caller. Additionally, the file contains a wget fallback (lines 94–119) that constructs a shell command with the unsanitized URL, introducing potential shell injection risk. No preconditions are required — the endpoint is publicly accessible without authentication (GitHub Advisory).

Impact

An unauthenticated remote attacker can leverage this vulnerability to probe localhost and internal network services, enumerate open and closed ports by observing connection-refused versus successful responses, access cloud instance metadata endpoints (e.g., http://169.254.169.254/) if reachable from the server, and retrieve the full body of internal HTTP responses. The primary impact is high confidentiality loss — sensitive internal service data, credentials, or cloud metadata may be exfiltrated — with a low integrity impact due to the ability to interact with internal services. No direct unauthenticated code execution was validated from this specific issue in the tested environment, though it can serve as a stepping stone for further attacks (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of concrete curl commands that demonstrate port probing and internal service interaction against a live AVideo deployment. The EPSS score is approximately 0.041% (0.000410), indicating a currently low but non-zero probability of exploitation in the wild. There is no evidence of active in-the-wild exploitation at this time, no known threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog. Qualys has added detection for this CVE (detection ID 5009456) (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing AVideo instances (version ≤ 26.0) using search engines like Shodan or Censys, looking for the AVideo web interface or the path /plugin/Live/test.php.
  2. Verify endpoint exposure: Send a basic request to confirm the endpoint is accessible: curl -s 'http://<TARGET>/plugin/Live/test.php?statsURL=http://127.0.0.1:80/'. A response containing server-side output (e.g., upstream HTTP headers or content) confirms the endpoint is live and vulnerable.
  3. Port enumeration: Probe closed ports to distinguish open vs. closed services by observing the reflected error output: curl -s 'http://<TARGET>/plugin/Live/test.php?statsURL=http://127.0.0.1:1/'. A Connection refused error in the response indicates a closed port; a successful response body indicates an open service.
  4. Internal service interaction: Target known internal service ports (e.g., 8080, 6379 for Redis, 9200 for Elasticsearch) to retrieve service banners or data: curl -s 'http://<TARGET>/plugin/Live/test.php?statsURL=http://127.0.0.1:9200/'.
  5. Cloud metadata access: If the server is hosted on a cloud provider, attempt to access the instance metadata endpoint: curl -s 'http://<TARGET>/plugin/Live/test.php?statsURL=http://169.254.169.254/latest/meta-data/'. A successful response may yield IAM credentials, instance identity, or other sensitive cloud configuration data (GitHub Advisory).

Indicators of compromise

  • Network: Unusual outbound HTTP requests originating from the AVideo web server process to loopback (127.0.0.1), RFC1918 addresses (10.x.x.x, 172.16-31.x.x, 192.168.x.x), or cloud metadata IPs (169.254.169.254); multiple rapid sequential requests to different ports on internal hosts.
  • Logs: Web server access logs showing repeated GET or POST requests to /plugin/Live/test.php with a statsURL parameter containing internal IP addresses, loopback addresses, or metadata endpoints; PHP error log entries containing file_get_contents failure messages referencing internal hosts (e.g., Failed to open stream: Connection refused for http://127.0.0.1:<port>/).
  • Application Logs: AVideo application logs (_log entries) showing file_get_contents:: output with internal service responses or error messages reflected from internal hosts.
  • Process: Unexpected wget child processes spawned by the PHP/web server process with URLs pointing to internal network resources (GitHub Advisory).

Mitigation and workarounds

The recommended remediation is to update AVideo to version 26.1 or later, which includes the patch in commit 1e6cf03e93b5a5318204b010ea28440b0d9a5ab3. If immediate upgrade is not possible, the safest workaround is to remove plugin/Live/test.php from production deployments entirely, or block public access to it via web server configuration (Apache/Nginx deny rules). If the file must remain, add admin authentication (User::isAdmin() check), restrict statsURL to an explicit allowlist of trusted Live stats URLs, block requests to localhost/RFC1918/link-local/metadata IP ranges using an isSSRFSafeURL() function (already available in objects/functions.php), stop reflecting fetched bodies and raw upstream errors to the client, and remove or sanitize the wget fallback using escapeshellarg(). Additionally, implement network-level egress filtering to block the web server process from reaching internal RFC1918 and metadata addresses (GitHub Advisory).

Community reactions

The vulnerability received coverage from security news outlets including The Hacker Wire and SecurityOnline.info, the latter covering multiple critical AVideo vulnerabilities disclosed simultaneously. Social media discussion was noted on Mastodon and Bluesky, with automated CVE tracking accounts amplifying the advisory. The yazoul.net security blog published a dedicated advisory writeup. Overall community sentiment treated this as a moderate-to-high severity finding given the zero-authentication requirement, though the absence of direct code execution limited alarm compared to the co-disclosed CSRF/RCE issue (CVE-2026-33507) (The Hacker Wire, SecurityOnline).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management