Server-Side Request Forgery in youtube-downloader
The youtube-downloader package contains an SSRF vulnerability in the stream function of public/stream.php allowing remote attackers to perform unauthorized outbound requests.
CVE search metadata
CVE search record: CVE-2026-100901. Severity: high. CVSS: 7.3. KEV: no. Product: youtube-downloader (<= 4.0.1). Brief: Server-Side Request Forgery in youtube-downloader. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ssrf/
A server-side request forgery (SSRF) vulnerability has been identified in the athlon1600 youtube-downloader project, affecting versions up to 4.0.1. The flaw exists within the 'stream' function of the 'public/stream.php' file, where user-supplied input via the 'url' argument is not correctly sanitized or validated before being used to initiate outbound requests.
Although a patch attempt (commit 6ffe823) was introduced to mitigate potential issues by adding 'CURLOPT_PROTOCOLS' restrictions and a 'MAXREDIRS' cap, the implementation fails to restrict the destination host, leaving the application vulnerable to remote exploitation. The vulnerability allows an attacker to force the server to initiate arbitrary HTTP or HTTPS requests, potentially exposing internal network resources or sensitive metadata services to unauthorized access. The vendor has remained unresponsive to disclosure attempts regarding this flaw.
Impact
Successful exploitation of this vulnerability allows an unauthenticated remote attacker to perform SSRF attacks. This may result in unauthorized access to internal network services, private APIs, or cloud metadata endpoints that are otherwise inaccessible from the public internet, potentially leading to data exfiltration or internal reconnaissance.
Recommendation
- Audit web server access logs for requests directed at 'public/stream.php' containing suspicious 'url' parameter values targeting internal IP addresses (e.g., 169.254.169.254, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16).
- Implement an allowlist of permitted destination domains or URL patterns for the 'stream' function if the application requirements permit.
- Restrict outbound network traffic from web server instances to prevent unauthorized internal scanning, particularly toward sensitive infrastructure segments.
Immediate actions
Review logs for exploit attempts targeting CVE-2026-100901 using the provided Sigma rule.
Threat Hunt
Search logs for inbound requests to public/stream.php
Data: Web server logs
Mitigations
Disable access to the vulnerable public/stream.php script or deploy a WAF rule blocking external access.
CVE-2026-100901
Detection coverage 1
Detect CVE-2026-100901 Exploitation - SSRF in youtube-downloader
highDetects potential SSRF attempts targeting the public/stream.php endpoint with internal or private IP address ranges in the url parameter.
Detection queries are available on the platform. Get full rules →