CVE-2026-72748

Source
https://cve.org/CVERecord?id=CVE-2026-72748
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72748.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72748
Aliases
  • GHSA-v7p7-jccx-h37c
Published
2026-08-11T12:17:02.126Z
Modified
2026-08-13T04:02:46.505929188Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
AVideo Unauthenticated Arbitrary File Write via aVideoEncoderChunk.json.php
Details

AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authentication. Attackers can exhaust disk space causing denial of service, poison the video encoding pipeline, or chain this with local file inclusion to achieve remote code execution.

Database specific
{
    "cwe_ids": [
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72748.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/wwbn/avideo

Affected ranges

Type
GIT
Repo
https://github.com/wwbn/avideo
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "29.0"
        },
        {
            "last_affected": "29.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

29.*
29.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72748.json"