{"id":"CVE-2026-85163","title":"AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG parser that allows authenticated uploaders to fetch arbitrary internal URLs","summary":"AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG parser that allows authenticated uploaders to fetch arbitrary internal URLs. An attacker can supply an internal URL via the epg_link paramete…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-918"],"published":"2026-09-03","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:18:59.270","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85163","references":[{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-r69x-6mr2-q23v","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/avideo-server-side-request-forgery-via-epg-link-parameter","label":"disclosure@vulncheck.com"},{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-r69x-6mr2-q23v","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.00209,"epssPercentile":0.11315,"ingestedAt":"2026-09-08T21:11:12.290Z","slug":"CVE-2026-85163","body":"## Overview\n\nAVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG parser that allows authenticated uploaders to fetch arbitrary internal URLs. An attacker can supply an internal URL via the epg_link parameter during video upload, which is validated only for syntax and later fetched server-side during EPG generation without SSRF protection checks.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}