CVE-2026-45619: Wwbn Avideo
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the $resolvedIP out-param of isSSRFSafeURL() for DNS pinning via CURLOPT_RESOLVE, opening DNS-rebinding TOCTOU.
Affected products
- Wwbn Avideo: up to and including 29.0
Published 2026-05-29. Last modified 2026-07-21.