CVE-2026-41055: AVideo has an incomplete fix for CVE-2026-33039 (SSRF)
WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks proxy adds isSSRFSafeURL() validation but leaves DNS TOCTOU vulnerabilities where DNS rebinding between validation and the actual HTTP request redirects traffic to internal endpoints. Commit 8d8fc0cadb425835b4861036d589abcea4d78ee8 contains an updated fix.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41055?
CVE-2026-41055 is classified as a medium severity vulnerability that involves an incomplete fix for SSRF in AVideo.
How do I fix CVE-2026-41055?
To mitigate CVE-2026-41055, upgrade AVideo to versions above 29.0 to ensure the complete remediation of the SSRF vulnerability.
What type of vulnerability is CVE-2026-41055?
CVE-2026-41055 is a Server-Side Request Forgery (SSRF) vulnerability that is exacerbated by DNS TOCTOU issues.
Which versions of AVideo are affected by CVE-2026-41055?
AVideo versions up to and including 29.0 are affected by CVE-2026-41055.
How does CVE-2026-41055 impact AVideo users?
CVE-2026-41055 can potentially allow attackers to exploit the incomplete SSRF fix to access internal resources, leading to data leakage.