CVE-2026-26005 Details
Description
ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #45, in Clip Bucket V5, The Remote Play allows creating video entries that reference external video URLs without uploading the video files to the server. However, by specifying an internal network host in the video URL, an SSRF can be triggered, causing GET requests to be sent to internal servers. An attacker can exploit this to scan the internal network. Even a regular (non-privileged) user can carry out the attack.
A server-side request forgery (SSRF) vulnerability has been identified in ClipBucket version 5 prior to 5.5.3 - #45. The issue arises in the Remote Play feature, which allows users to create video entries by referencing external video URLs without uploading the actual video files to the server. However, by inserting an internal network host in the video URL, an attacker can trigger the SSRF vulnerability, causing GET requests to be sent to internal servers. This exploitation can be used to scan the internal network for accessible services and hosts. Notably, this vulnerability can be exploited by regular (non-privileged) users.
Users can update to ClipBucket version 5.5.3 - #45 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| oxygenz clipbucket | >= 5.3, < 5.5.3-45 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 18, 2026 | Initial Analysis | [email protected] |
| Feb 12, 2026 | New CVE Received | [email protected] |