Skip to content
Threat Feed
high advisory

Server-Side Request Forgery in youtube-downloader

The youtube-downloader package contains an SSRF vulnerability in the stream function of public/stream.php allowing remote attackers to perform unauthorized outbound requests.

CVE search metadata

CVE search record: CVE-2026-100901. Severity: high. CVSS: 7.3. KEV: no. Product: youtube-downloader (<= 4.0.1). Brief: Server-Side Request Forgery in youtube-downloader. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ssrf/

A server-side request forgery (SSRF) vulnerability has been identified in the athlon1600 youtube-downloader project, affecting versions up to 4.0.1. The flaw exists within the 'stream' function of the 'public/stream.php' file, where user-supplied input via the 'url' argument is not correctly sanitized or validated before being used to initiate outbound requests.

Although a patch attempt (commit 6ffe823) was introduced to mitigate potential issues by adding 'CURLOPT_PROTOCOLS' restrictions and a 'MAXREDIRS' cap, the implementation fails to restrict the destination host, leaving the application vulnerable to remote exploitation. The vulnerability allows an attacker to force the server to initiate arbitrary HTTP or HTTPS requests, potentially exposing internal network resources or sensitive metadata services to unauthorized access. The vendor has remained unresponsive to disclosure attempts regarding this flaw.

Impact

Successful exploitation of this vulnerability allows an unauthenticated remote attacker to perform SSRF attacks. This may result in unauthorized access to internal network services, private APIs, or cloud metadata endpoints that are otherwise inaccessible from the public internet, potentially leading to data exfiltration or internal reconnaissance.

Recommendation

  1. Audit web server access logs for requests directed at 'public/stream.php' containing suspicious 'url' parameter values targeting internal IP addresses (e.g., 169.254.169.254, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16).
  2. Implement an allowlist of permitted destination domains or URL patterns for the 'stream' function if the application requirements permit.
  3. Restrict outbound network traffic from web server instances to prevent unauthorized internal scanning, particularly toward sensitive infrastructure segments.

Immediate actions

Review logs for exploit attempts targeting CVE-2026-100901 using the provided Sigma rule.

SOC 24h

Threat Hunt

Search logs for inbound requests to public/stream.php

T1190 high high confidence hunt now

Data: Web server logs

Mitigations

Disable access to the vulnerable public/stream.php script or deploy a WAF rule blocking external access.

immediate IT Operations

CVE-2026-100901

Detection coverage 1

Detect CVE-2026-100901 Exploitation - SSRF in youtube-downloader

high

Detects potential SSRF attempts targeting the public/stream.php endpoint with internal or private IP address ranges in the url parameter.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →