#VU125499 Server-Side Request Forgery (SSRF) in AVideo - CVE-2026-34740
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote user to perform server-side requests to arbitrary internal and external targets and disclose sensitive information.
The vulnerability exists due to server-side request forgery in the EPG link processing path when handling a stored user-supplied EPG URL. A remote user can store a crafted URL that the server fetches on subsequent EPG page visits to perform server-side requests to arbitrary internal and external targets and disclose sensitive information.
The issue is persistent because the URL is stored and re-fetched on every EPG page visit.