Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-91967— AVideo through 29.0 Blind SSRF via getHeaderContentTypeFromURL

Quick assessment

Affected
WWBN AVideo
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

AVideo 29.0 及以下版本存在一个盲型的服务器端请求伪造(blind SSRF)漏洞,位于 函数中。该函数执行 调用时,仅受到格式校验的保护,缺乏更严格的源地址限制。 拥有 权限的已认证用户可以存储攻击者选定的 URL 作为视频链接;随后,每当视频观看页面渲染时,都会触发该易受攻击函数的执行,从而利用内容类型预言机(content-type oracle)和基于时序的检测机制,对内部主机进行探测。

CVSS 5.0 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-91967

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
AVideo through 29.0 Blind SSRF via getHeaderContentTypeFromURL
Source: CVE Program / CVE List V5
Vulnerability Description
AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL function that issues get_headers() calls guarded only by format validation. Authenticated users with canUpload permission can store attacker-chosen URLs as video links, triggering vulnerable function execution on every video watch page render to probe internal hosts using content-type oracles and timing-based detection.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
WWBN AVideo 0 ~ 29.0 -

II. Public POCs for CVE-2026-91967

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-91967

登录查看更多情报信息。

Vendor Advisories for CVE-2026-91967 (2)

Same Patch Batch · WWBN · 2026-09-15 · 3 CVEs total

CVE-2026-91965 7.5 HIGH WWBN AVideo through 29.0 Broken Access Control via Live Endpoints
CVE-2026-91966 5.8 MEDIUM AVideo through 29.0 Unauthenticated SSRF via Host Header

IV. Related Vulnerabilities

V. Comments for CVE-2026-91967

No comments yet


Leave a comment