CVE-2026-41055 - Vulnerability Analysis
HighCVSS: 8.6Last Updated: April 21, 2026
WWBN AVideo - Server Side Request Forgery
Overview
WWBN AVideo <= 29.0 contains a server side request forgery caused by DNS TOCTOU vulnerability in LiveLinks proxy's isSSRFSafeURL() validation, letting attackers redirect traffic to internal endpoints, exploit requires network access.
Severity & Score
Impact
Attackers can redirect traffic to internal endpoints, potentially accessing or manipulating internal services.
Mitigation
Update to the version including commit 8d8fc0cadb425835b4861036d589abcea4d78ee8 or latest available version.
References
Social Media Activity(2 posts)
š CVE-2026-41055 - High (8.6) WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks proxy adds `isSSRFSafeURL()` validation but leaves DNS TOCTOU vulnerabilities where DNS rebinding between validation and the act... š https://www.thehackerwire.com/vulnerability/CVE-2026-41055/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš CVE-2026-41055 - High (8.6) WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks proxy adds `isSSRFSafeURL()` validation but leaves DNS TOCTOU vulnerabilities where DNS rebinding between validation and the act... š https://www.thehackerwire.com/vulnerability/CVE-2026-41055/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-41055
- Severity
- High
- CVSS Score
- 8.6
- Type
- server_side_request_forgery
- Status
- new
- EPSS
- 0.0%
- Social Posts
- 2
CWE
- CWE-918
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N