Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100901— athlon1600 youtube-downloader stream.php stream server-side request forgery

Quick assessment

Affected
athlon1600 youtube-downloader
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 athlon1600 开发的 youtube-downloader(版本最高至 4.0.1)中发现了一处漏洞。受影响的是文件 中的 函数。对参数 的操纵可导致服务器端请求伪造(SSRF)。该漏洞可被远程利用。相关利用代码已被公开,可被实际使用。提交记录 (旨在“提升 public/stream.php 的安全性”)仅限制了 CURLOPT_PROTOCOLS 为 http/https,并设置了最大重定向次数(MAXREDIRS),但并未对目标主机进行限制。开发者早在披露前就已收到通知,但未做出任何回应。

CVSS 7.3 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100901

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
athlon1600 youtube-downloader stream.php stream server-side request forgery
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this vulnerability is the function stream of the file public/stream.php. The manipulation of the argument url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. Commit 6ffe823 'better security for public/stream.php' only added CURLOPT_PROTOCOLS http/https restriction and MAXREDIRS cap, does not restrict destination host. The vendor was contacted early about this disclosure but did not respond in any way.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
athlon1600 youtube-downloader 4.0.0 cpe:2.3:a:athlon1600:youtube-downloader:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-100901

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100901

请登录查看更多情报信息。

Other References for CVE-2026-100901 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-100901

No comments yet


Leave a comment