CVE-2026-100901 Details
Description
A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this vulnerability is the function stream of the file public/stream.php. The manipulation of the argument url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. Commit 6ffe823 'better security for public/stream.php' only added CURLOPT_PROTOCOLS http/https restriction and MAXREDIRS cap, does not restrict destination host. The vendor was contacted early about this disclosure but did not respond in any way.
A server-side request forgery (SSRF) vulnerability has been identified in Athlon1600 YouTube-Downloader versions up to 4.0.1. The issue resides in the 'stream' function of 'public/stream.php', where user-supplied URLs are sent to cURL without proper validation. This flaw allows remote, unauthenticated attackers to make the server fetch any HTTP or HTTPS resource, including internal services and cloud metadata, and stream the full response back to the attacker.
To address this vulnerability, restrict the accepted URLs to only those from the YouTube CDN, implement a blocklist for loopback, private, and cloud metadata IPs, and optionally re-enable cURL's SSL peer and host verification.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/qianqiusujiu/87a7d7d8bd7fb53cf8529e0bafbeafba | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-100901 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/919147 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/410851 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/410851/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| athlon1600 youtube-downloader | <= 4.0.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion