{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/avideo-e01e41ecc-and-earlier/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-82648"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AVideo","AVideo (e01e41ecc and earlier)"],"_cs_severities":["high"],"_cs_tags":["credential-access","web-application","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":["WWBN"],"content_html":"\u003cp\u003eWWBN AVideo contains a server-side request forgery (SSRF) vulnerability identified as CVE-2026-82648, located within the isSSRFSafeURL function. The vulnerability stems from a failure to correctly normalize NAT64 addresses when they are presented in a hexadecimal format. Because the function does not account for these specific representations, attackers can bypass existing URL filtering protections. By crafting malicious requests containing NAT64 addresses such as 64:ff9b::a9fe:a9fe, an unauthorized actor can force the application to perform requests against restricted internal resources, including cloud metadata services (e.g., 169.254.169.254) and local loopback interfaces. This flaw is particularly significant in cloud-hosted environments where metadata services store sensitive IAM credentials or instance configuration details. Successful exploitation allows an attacker to interact with internal network segments that are otherwise protected from external reach, potentially resulting in credential theft or further lateral movement within the hosting infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to bypass SSRF protections, enabling unauthorized interaction with internal cloud metadata services and local network resources. This can result in the exfiltration of instance-level credentials, sensitive configuration data, or internal system exploitation, compromising the confidentiality and integrity of the AVideo server instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit web application logs for HTTP requests containing unusual IPv6 NAT64 or hex-encoded address strings directed at internal hostnames or IP ranges.\u003c/li\u003e\n\u003cli\u003eImplement a secondary validation layer at the network edge or application-level proxy to verify that requests originating from AVideo are not destined for reserved or private IP ranges, regardless of the encoding used in the URL.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized access attempts to local cloud metadata services from the AVideo application host.\u003c/li\u003e\n\u003cli\u003eReview all AVideo instance configurations to ensure they are updated to the latest vendor-provided patches that resolve CVE-2026-82648.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-30T19:11:23Z","date_published":"2026-08-30T17:11:37Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wwbn-avideo-ssrf/","summary":"WWBN AVideo is vulnerable to a Server-Side Request Forgery (SSRF) bypass in the isSSRFSafeURL function due to improper normalization of hex-encoded NAT64 addresses.","title":"WWBN AVideo SSRF Filter Bypass via NAT64 Hex Encoding","url":"https://feed.craftedsignal.io/briefs/2026-08-wwbn-avideo-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - AVideo (E01e41ecc and Earlier)","version":"https://jsonfeed.org/version/1.1"}