CVE-2026-41055: Wwbn Avideo

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks proxy adds `isSSRFSafeURL()` validation but leaves DNS TOCTOU vulnerabilities where DNS rebinding between validation and the actual HTTP request redirects traffic to internal endpoints. Commit 8d8fc0cadb425835b4861036d589abcea4d78ee8 contains an updated fix.

Affected products

  • Wwbn Avideo: up to and including 29.0

Published 2026-04-21. Last modified 2026-06-17.