CVE Disclosure

CVE-2026-45619

WWBN/AVideo · PHP

Incomplete fix for CVE-2026-43884 — 6+ isSSRFSafeURL() sites discard $resolvedIP out-param at master HEAD post-603e7bf

CVSS
SeverityMedium
StatusPublished

Summary

CVE-2026-45619 is a medium-severity vulnerability affecting WWBN/AVideo (PHP): Incomplete fix for CVE-2026-43884 — 6+ isSSRFSafeURL() sites discard $resolvedIP out-param at master HEAD post-603e7bf.

References

Disclosure

Reported by Kai Aizen. Status: Published. Coordinated through standard NVD/MITRE/GHSA channels.

disclosure contextall 30 cves →
Author
Kai Aizen
Independent offensive security researcher. 30 published CVEs, 5 Linux kernel mainline patches, creator of AATMF / P.R.O.M.P.T / SEF, author of Adversarial Minds.