High severity7.5NVD Advisory· Published Mar 23, 2026· Updated Jun 17, 2026
CVE-2026-33483
CVE-2026-33483
Description
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the aVideoEncoderChunk.json.php endpoint is a completely standalone PHP script with no authentication, no framework includes, and no resource limits. An unauthenticated remote attacker can send arbitrary POST data which is written to persistent temp files in /tmp/ with no size cap, no rate limiting, and no cleanup mechanism. This allows trivial disk space exhaustion leading to denial of service of the entire server. Commit 33d1bae6c731ef1682fcdc47b428313be073a5d1 contains a patch.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
wwbn/avideoPackagist | <= 26.0 | — |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/WWBN/AVideo/commit/33d1bae6c731ef1682fcdc47b428313be073a5d1nvdPatchWEB
- github.com/WWBN/AVideo/security/advisories/GHSA-vv7w-qf5c-734wnvdExploitMitigationVendor AdvisoryWEB
- github.com/advisories/GHSA-vv7w-qf5c-734wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-33483ghsaADVISORY
News mentions
0No linked articles in our index yet.