Vulnerability Description
AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL function that issues get_headers() calls guarded only by format validation. Authenticated users with canUpload permission can store attacker-chosen URLs as video links, triggering vulnerable function execution on every video watch page render to probe internal hosts using content-type oracles and timing-based detection.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/WWBN/AVideo/security/advisories/GHSA-vjgr-5x63-cq96
- https://www.vulncheck.com/advisories/avideo-through-29.0-blind-ssrf-via-getheade
- https://github.com/WWBN/AVideo/security/advisories/GHSA-vjgr-5x63-cq96
FAQ
What is CVE-2026-91967?
CVE-2026-91967 is a vulnerability with a CVSS score of 5.0 (MEDIUM). AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL function that issues get_headers() calls guarded only by format validation. Authentica...
How severe is CVE-2026-91967?
CVE-2026-91967 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-91967?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.