CVE-2026-33766: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33766 is a Server-Side Request Forgery (SSRF) protection bypass vulnerability in WWBN AVideo, an open source video platform. The flaw exists in versions up to and including 26.0, where the isSSRFSafeURL() function validates URLs before fetching but url_get_contents() follows HTTP redirects without re-validating the redirect target, allowing an attacker to bypass SSRF protections via an open redirect chain. The vulnerability was published on March 24, 2026, and assigned CVE-2026-33766 (Github Advisory). It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (Github Advisory).

Technical details

The root cause is a Time-of-Check/Time-of-Use (TOCTOU) flaw classified as CWE-918 (Server-Side Request Forgery). At check-time, isSSRFSafeURL() in objects/functions.php (line 4066) resolves the hostname and validates the IP against private/reserved ranges. At use-time, url_get_contents() (line 1990) calls PHP's file_get_contents() with the default follow_location=1, silently following HTTP redirects to the final destination without re-invoking the SSRF check; the wget fallback (line 2047) similarly follows redirects by default. The vulnerable endpoint is objects/aVideoEncoderReceiveImage.json.php at multiple lines (67-68, 107-108, 135-136, 160-161), which accepts a user-supplied downloadURL_image parameter. Notably, the curl path in url_get_contents() does not set CURLOPT_FOLLOWLOCATION and is therefore not affected — only the file_get_contents and wget fallback paths are vulnerable (AVideo Advisory).

Impact

Successful exploitation allows an attacker to make the AVideo server issue requests to internal network resources that would otherwise be blocked by SSRF protections, including cloud instance metadata endpoints (AWS IMDSv1 at 169.254.169.254, GCP, Azure). This can expose sensitive cloud credentials, internal service data, and configuration information, with low confidentiality and low integrity impact on the vulnerable system. Availability is not directly impacted, but access to cloud metadata credentials could enable lateral movement or privilege escalation within a cloud environment (Github Advisory, AVideo Advisory).

Exploitability

A proof-of-concept exploit sequence is publicly documented in the GitHub Security Advisory, demonstrating a concrete redirect chain from a public attacker-controlled URL to an internal target (AVideo Advisory). The advisory notes that exploitation requires an authenticated user with upload and edit permissions to trigger the image download endpoint, introducing a user-interaction precondition. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.041% (0.035% per GitHub Advisory), placing it in the 11th percentile for exploitation likelihood (Github Advisory).

Exploitation steps

  1. Set up a redirect server: Configure an attacker-controlled server (e.g., https://attacker.com/redir) to respond to HTTP GET requests with a 302 Location redirect pointing to an internal target, such as http://169.254.169.254/latest/meta-data/ (AWS IMDSv1 endpoint).
  2. Identify a target AVideo instance: Locate an internet-facing AVideo deployment running version 26.0 or earlier.
  3. Obtain or social-engineer authenticated access: The vulnerable endpoint requires an authenticated user with upload and edit permissions to trigger the image download. The attacker either uses their own credentials or tricks a legitimate user into making the request.
  4. Trigger the vulnerable endpoint: Send a crafted GET request to the image download endpoint with the attacker-controlled redirect URL as the downloadURL_image parameter:
    GET /objects/aVideoEncoderReceiveImage.json.php?downloadURL_image=https://attacker.com/redir&...
  5. Bypass SSRF validation: isSSRFSafeURL() resolves attacker.com to a public IP and passes validation.
  6. Follow redirect to internal target: url_get_contents() calls file_get_contents() which follows the 302 redirect to http://169.254.169.254/latest/meta-data/ without re-validating the destination, returning the internal resource's content to the attacker (AVideo Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from the AVideo server to 169.254.169.254 (AWS IMDSv1), metadata.google.internal, or 169.254.169.254 (Azure IMDS); unexpected outbound connections to attacker-controlled domains followed by connections to internal RFC-1918 or link-local addresses.
  • Logs: Web server access logs showing GET requests to /objects/aVideoEncoderReceiveImage.json.php with downloadURL_image parameters pointing to external domains not associated with legitimate media sources; PHP error logs containing entries matching url_get_contents: blocked unsafe redirect (if the patched version is deployed and blocking attempts).
  • Application Logs: Entries in AVideo application logs showing image download attempts from unusual or newly registered external domains, particularly those that resolve to public IPs but redirect to internal ranges.

Mitigation and workarounds

The vendor has released a patch in commit 8b7e9dad359d5fac69e0cbbb370250e0b284bc12, which disables automatic redirect following in both url_get_contents() (by setting follow_location=0 in the PHP stream context) and the wget fallback (by adding --max-redirect=0), then manually re-validates each redirect hop with isSSRFSafeURL() before following it (Patch Commit). Users should upgrade WWBN AVideo to a version newer than 26.0 that includes this patch. As a network-level workaround, implement egress filtering on the AVideo server to block outbound connections to private/reserved IP ranges (RFC-1918, link-local 169.254.0.0/16) and cloud metadata endpoints (Github Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management