VYPR

nitter

by Zedeus

CVEs (1)

  • CVE-2026-56285Jun 29, 2026
    risk 0.00cvss epss 0.00

    Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute valid HMACs for arbitrary URLs. Attackers can retrieve HTTP responses from any host reachable by the…