
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34740 is a stored Server-Side Request Forgery (SSRF) vulnerability in WWBN AVideo, an open source video platform. It affects AVideo versions 26.0 and prior, where the EPG (Electronic Program Guide) link feature allows authenticated users with upload permissions to store arbitrary URLs that the server fetches on every EPG page visit. The vulnerability was published on March 30–31, 2026, and discovered by aisafe.io. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Github Advisory).
The root cause is CWE-918 (Server-Side Request Forgery), stemming from insufficient URL validation in the EPG link processing path. When a video is created or edited, the EPG link is stored via objects/videoAddNew.json.php:119 using only PHP's FILTER_VALIDATE_URL, which accepts internal network addresses such as http://127.0.0.1, http://169.254.169.254, or http://10.0.0.1. The stored URL is later fetched server-side at objects/EpgParser.php:358 via file_get_contents($this->url), which follows redirects and supports multiple protocols (http, https, ftp, and potentially php:// stream wrappers). Although AVideo contains a dedicated isSSRFSafeURL() function used in other code paths, it is never called during EPG link processing, leaving this path entirely unprotected (GitHub Advisory).
Successful exploitation allows an authenticated attacker to force the AVideo server to make HTTP requests to arbitrary internal and external targets on every EPG page visit, making the SSRF persistent and repeatable without further attacker interaction. This enables internal network scanning, access to cloud instance metadata services (potentially exposing IAM credentials on AWS, GCP, or Azure via http://169.254.169.254), and interaction with internal services not intended to be externally accessible (e.g., Redis on port 6379). The primary impact is high confidentiality loss, with no direct integrity or availability impact (GitHub Advisory, Github Advisory).
A proof-of-concept exploit consisting of concrete, step-by-step curl commands targeting real AVideo endpoints is publicly available in the GitHub Security Advisory (GitHub Advisory). Exploitation requires low privileges (an account with upload permissions) and no user interaction beyond the initial payload submission. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.023%, indicating a low near-term exploitation probability (Github Advisory).
PHPSESSID cookie.objects/videoAddNew.json.php with the epg_link parameter set to an internal target, such as the AWS cloud metadata endpoint:curl -b "PHPSESSID=USER_SESSION" \
-X POST "https://your-avideo-instance.com/objects/videoAddNew.json.php" \
-d "title=Test+Video&epg_link=http://169.254.169.254/latest/meta-data/iam/security-credentials/"file_get_contents():curl -b "PHPSESSID=USER_SESSION" \
"https://your-avideo-instance.com/plugin/Live/view/Live_schedule/?videos_id=VIDEO_ID"http://127.0.0.1:6379/ for Redis) to map internal services; response timing and error messages reveal open ports (GitHub Advisory).169.254.169.254, 127.0.0.1, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or cloud metadata endpoints; unusual outbound connections to non-standard ports (e.g., 6379 for Redis, 2375 for Docker API)./objects/videoAddNew.json.php with epg_link parameters containing internal IP addresses or metadata service URLs; PHP error logs showing file_get_contents() calls to internal addresses from objects/EpgParser.php.http://169.254.169.254, http://127.0.0.1, http://10.*, http://192.168.*) instead of legitimate external EPG feed URLs./plugin/Live/view/Live_schedule/?videos_id=VIDEO_ID from different source IPs, indicating the stored SSRF is being triggered by multiple visitors (GitHub Advisory).As of the time of publication, no official patch is available for CVE-2026-34740. The recommended fix is to add an isSSRFSafeURL() check before the file_get_contents() call in objects/EpgParser.php:355:
if (function_exists('isSSRFSafeURL') && !isSSRFSafeURL($this->url)) {
throw new \RuntimeException('URL blocked by SSRF protection');
}Workarounds include restricting upload permissions to trusted users only, implementing firewall or egress filtering rules to block the AVideo server from making outbound connections to internal network ranges and cloud metadata endpoints, enabling network segmentation, and considering disabling the EPG link feature entirely until a patch is released (GitHub Advisory, Github Advisory).
The vulnerability was discovered and reported by aisafe.io and credited to researcher adrgs, with the advisory published by DanielnetoDotCom on March 30, 2026 (GitHub Advisory). The advisory was noted on Bluesky and tracked by multiple vulnerability aggregators including VulDB, CVEFeed, and Radar shortly after publication. No significant vendor statement or broader media coverage has been identified beyond the GitHub Security Advisory.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."