
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-39368 is a Stored Server-Side Request Forgery (SSRF) vulnerability in WWBN AVideo, an open source video platform. The flaw exists in the Live restream log callback flow, where an attacker-controlled restreamerURL is accepted and later fetched server-side, enabling authenticated streamers to proxy requests to internal or loopback services. All versions up to and including 26.0 are affected; no patched version has been released as of the advisory date. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, GHSA-q4x6-6mm2-crg9).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and stems from the absence of URL validation on the restreamerURL parameter at storage time in the Live restream log feature. The exploitable chain involves four endpoints: getRestream.json.php exposes a tokenForAction, verifyTokenForAction.json.php exchanges it for a responseToken, Live_restreams_logs/add.json.php accepts an attacker-controlled restreamerURL without constraining it to trusted destinations, and subsequent calls to getRestream.json.php or getAction.json.php fetch the stored URL server-side. Because the responseToken was accepted without binding it to an expected callback host, any HTTP-reachable address — including loopback (127.0.0.1) and RFC-1918 internal ranges — could be specified as the callback destination (GitHub Advisory, GHSA-q4x6-6mm2-crg9).
Successful exploitation allows an authenticated low-privilege streamer to use the AVideo server as an HTTP proxy to internal-only services, effectively bypassing network access controls that rely on network locality. Sensitive assets that could be exposed include local admin panels, internal-only APIs, and cloud instance metadata services (e.g., 169.254.169.254). The impact is limited to confidentiality (CVSS Confidentiality: High) with no direct integrity or availability impact, though data obtained from internal services could facilitate further lateral movement or privilege escalation (GHSA-q4x6-6mm2-crg9).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been observed as of the advisory date. The vulnerability requires an authenticated account with streaming permissions, limiting the attacker pool but not eliminating risk in multi-tenant or community-facing deployments. The EPSS score is approximately 0.036% (11th percentile), indicating a low near-term exploitation probability. The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory).
POST /plugin/Live/view/Live_restreams/testRestreamer.json.php to create a live transmission history entry.GET /plugin/Live/view/getRestream.json.php?live_transmitions_history_id=<id>&restreams_id=<id> and extract the tokenForAction value from the response.POST /plugin/Live/view/Live_restreams/verifyTokenForAction.json.php with the extracted token to receive a valid responseToken.POST /plugin/Live/view/Live_restreams_logs/add.json.php with restreamerURL=http://127.0.0.1:9999/index.php (or any internal target) using the responseToken.GET /plugin/Live/view/getRestream.json.php again; the server fetches the stored loopback URL and returns the internal service's response through the normal application endpoint, exposing internal data to the attacker (GHSA-q4x6-6mm2-crg9).127.0.0.1, ::1) or RFC-1918 addresses (10.x.x.x, 172.16–31.x.x, 192.168.x.x) originating from the web server process; requests to cloud metadata endpoints such as 169.254.169.254./plugin/Live/view/Live_restreams_logs/add.json.php with non-standard restreamerURL values; GET requests to /plugin/Live/view/getRestream.json.php shortly after such POSTs from the same session.No patched version of WWBN AVideo has been released as of the advisory date (affected versions ≤ 26.0). The maintainer confirmed the fix approach involves validating restreamerURL against explicitly configured restreamer endpoints at storage time and re-validating before any server-side fetch. Until a patch is available, operators should implement network egress controls to block the AVideo server from making outbound requests to loopback and internal IP ranges, restrict the Live restream feature to highly trusted users, and monitor callback URL configurations for suspicious patterns (GHSA-q4x6-6mm2-crg9, GitHub Advisory).
The vulnerability was reported by researcher threalwinky and published by maintainer DanielnetoDotCom on April 6, 2026. The maintainer confirmed the vulnerability and described the intended fix approach in the advisory. No significant broader media coverage or notable community commentary beyond the GitHub advisory has been identified (GHSA-q4x6-6mm2-crg9).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."