CVE-2026-33024 identifies a critical Server-Side Request Forgery (SSRF) vulnerability (CWE-918) in AVideo (wwbn avideo_encoder) versions prior to 8.0. This flaw allows unauthenticated attackers to manipulate public thumbnail endpoints to force the server to make requests to arbitrary internal network resources, such as cloud metadata services or private IP addresses. With a CVSS score of 9.1 Critical, the vulnerability poses a high risk of confidentiality and integrity compromise, even though the response is blind. There is currently no evidence of active exploitation, public exploit code, or significant media coverage, though it has garnered some community discussion. Organizations using affected versions should upgrade to AVideo 8.0 or implement strict outbound traffic filtering to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.0CPE matchmatch criteria | cpe:2.3:a:wwbn:avideo-encoder:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.