Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-19913

Quick assessment

Affected
Kaltura Kaltura HTML5 Video Player, html5lib library
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kaltura HTML5 播放器(mwEmbed / html5lib)存在本地文件披露漏洞。该漏洞源于 mwEmbedLoader.php 中对 ServiceUrl 参数验证不当。此参数被用作后端请求的基础 URL,并允许使用 file:// 等非 HTTP 协议。当发生异常或错误时,响应内容会被反序列化,其原始内容会通过错误消息反射返回给客户端;这使得未认证的远程攻击者能够读取服务器可达的任意内部文件。受影响的版本包括 html5lib v2.45、v2.103 及更早版本,以及其他 v2.x 系列中暴露了

AI Predicted 9.1 Difficulty: Easy EPSS 0.19% · P8

Affected Version Matrix 2

VendorProduct Version RangeStatus
Kaltura Kaltura HTML5 Video Player, html5lib library ≤ v2.103 affected
2.45 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19913

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CVE-2026-19913
Source: CVE Program / CVE List V5
Vulnerability Description
The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter is used as the base URL for a backend request and accepts non‑HTTP schemes such as file://. When an exception or error occurs, the response is subsequently deserialized and its raw contents are reflected to the client in an error message; this enables an unauthenticated, remote attacker to read any arbitrary internal file reachable by the server. Affected versions include html5lib v2.45, v2.103 and earlier, and other v2.x releases exposing the vulnerable endpoint.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Kaltura Kaltura HTML5 Video Player, html5lib library 0 ~ v2.103 -

II. Public POCs for CVE-2026-19913

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19913

登录查看更多情报信息。

Vendor Advisories for CVE-2026-19913 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-19913

No comments yet


Leave a comment