PT-2026-61743 · Avideo · Avideo

CVE-2026-64626

·

Published

2026-07-20

·

Updated

2026-07-21

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions 0dbadbca through latest master
Description An authenticated attacker can perform blind Server-Side Request Forgery (SSRF) attacks by exploiting the encoder download-by-URL flow. The issue occurs because an unpinned retry fallback bypasses DNS pinning validation. By providing a downloadURL that redirects to an internal address, the attacker can force the system to follow the redirect and reach internal targets.
Recommendations Update AVideo to a version where the DNS pinning validation is correctly enforced during the retry fallback in the encoder download-by-URL flow.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64626

Affected Products

Avideo