{"id":"CVE-2026-82648","title":"WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form","summary":"WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers can bypass SSRF protections by supplying hex-enco…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N","cwe":["CWE-20"],"published":"2026-08-30","updated":"2026-08-30","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82648","references":[{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-88jm-rxg9-3v5r","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wwbn-avideo-ssrf-filter-bypass-via-nat64-hex-address","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"ingestedAt":"2026-08-30T23:59:28.575Z","epss":0.00315,"epssPercentile":0.21754,"slug":"CVE-2026-82648","body":"## Overview\n\nWWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers can bypass SSRF protections by supplying hex-encoded NAT64 addresses like 64:ff9b::a9fe:a9fe to reach cloud metadata services and loopback interfaces.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}