
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33766 is a Server-Side Request Forgery (SSRF) protection bypass vulnerability in WWBN AVideo, an open source video platform. The flaw exists in versions up to and including 26.0, where the isSSRFSafeURL() function validates URLs before fetching but url_get_contents() follows HTTP redirects without re-validating the redirect target, allowing an attacker to bypass SSRF protections via an open redirect chain. The vulnerability was published on March 24, 2026, and assigned CVE-2026-33766 (Github Advisory). It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (Github Advisory).
The root cause is a Time-of-Check/Time-of-Use (TOCTOU) flaw classified as CWE-918 (Server-Side Request Forgery). At check-time, isSSRFSafeURL() in objects/functions.php (line 4066) resolves the hostname and validates the IP against private/reserved ranges. At use-time, url_get_contents() (line 1990) calls PHP's file_get_contents() with the default follow_location=1, silently following HTTP redirects to the final destination without re-invoking the SSRF check; the wget fallback (line 2047) similarly follows redirects by default. The vulnerable endpoint is objects/aVideoEncoderReceiveImage.json.php at multiple lines (67-68, 107-108, 135-136, 160-161), which accepts a user-supplied downloadURL_image parameter. Notably, the curl path in url_get_contents() does not set CURLOPT_FOLLOWLOCATION and is therefore not affected — only the file_get_contents and wget fallback paths are vulnerable (AVideo Advisory).
Successful exploitation allows an attacker to make the AVideo server issue requests to internal network resources that would otherwise be blocked by SSRF protections, including cloud instance metadata endpoints (AWS IMDSv1 at 169.254.169.254, GCP, Azure). This can expose sensitive cloud credentials, internal service data, and configuration information, with low confidentiality and low integrity impact on the vulnerable system. Availability is not directly impacted, but access to cloud metadata credentials could enable lateral movement or privilege escalation within a cloud environment (Github Advisory, AVideo Advisory).
A proof-of-concept exploit sequence is publicly documented in the GitHub Security Advisory, demonstrating a concrete redirect chain from a public attacker-controlled URL to an internal target (AVideo Advisory). The advisory notes that exploitation requires an authenticated user with upload and edit permissions to trigger the image download endpoint, introducing a user-interaction precondition. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.041% (0.035% per GitHub Advisory), placing it in the 11th percentile for exploitation likelihood (Github Advisory).
https://attacker.com/redir) to respond to HTTP GET requests with a 302 Location redirect pointing to an internal target, such as http://169.254.169.254/latest/meta-data/ (AWS IMDSv1 endpoint).downloadURL_image parameter:GET /objects/aVideoEncoderReceiveImage.json.php?downloadURL_image=https://attacker.com/redir&...isSSRFSafeURL() resolves attacker.com to a public IP and passes validation.url_get_contents() calls file_get_contents() which follows the 302 redirect to http://169.254.169.254/latest/meta-data/ without re-validating the destination, returning the internal resource's content to the attacker (AVideo Advisory).169.254.169.254 (AWS IMDSv1), metadata.google.internal, or 169.254.169.254 (Azure IMDS); unexpected outbound connections to attacker-controlled domains followed by connections to internal RFC-1918 or link-local addresses./objects/aVideoEncoderReceiveImage.json.php with downloadURL_image parameters pointing to external domains not associated with legitimate media sources; PHP error logs containing entries matching url_get_contents: blocked unsafe redirect (if the patched version is deployed and blocking attempts).The vendor has released a patch in commit 8b7e9dad359d5fac69e0cbbb370250e0b284bc12, which disables automatic redirect following in both url_get_contents() (by setting follow_location=0 in the PHP stream context) and the wget fallback (by adding --max-redirect=0), then manually re-validates each redirect hop with isSSRFSafeURL() before following it (Patch Commit). Users should upgrade WWBN AVideo to a version newer than 26.0 that includes this patch. As a network-level workaround, implement egress filtering on the AVideo server to block outbound connections to private/reserved IP ranges (RFC-1918, link-local 169.254.0.0/16) and cloud metadata endpoints (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."