LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-41055

CVE-2026-41055 - Vulnerability Analysis

HighCVSS: 8.6

Last Updated: April 21, 2026

WWBN AVideo - Server Side Request Forgery

Published: April 21, 2026Updated: April 21, 2026Remote Exploitable

Overview

WWBN AVideo <= 29.0 contains a server side request forgery caused by DNS TOCTOU vulnerability in LiveLinks proxy's isSSRFSafeURL() validation, letting attackers redirect traffic to internal endpoints, exploit requires network access.

Severity & Score

Severity: High
CVSS Score: 8.6
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Attackers can redirect traffic to internal endpoints, potentially accessing or manipulating internal services.

Mitigation

Update to the version including commit 8d8fc0cadb425835b4861036d589abcea4d78ee8 or latest available version.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 21, 2026

🟠 CVE-2026-41055 - High (8.6) WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks proxy adds `isSSRFSafeURL()` validation but leaves DNS TOCTOU vulnerabilities where DNS rebinding between validation and the act... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-41055/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Apr 21, 2026

🟠 CVE-2026-41055 - High (8.6) WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks proxy adds `isSSRFSafeURL()` validation but leaves DNS TOCTOU vulnerabilities where DNS rebinding between validation and the act... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-41055/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-41055
Severity
High
CVSS Score
8.6
Type
server_side_request_forgery
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-918

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

EPSS Score

0.0%Probability of exploitation in the next 30 days