CVE 7.7 HIGH

Nitter – Server-Side Request Forgery in /video Media Proxy Endpoint_CVE-2026-56285

7.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:N/SA:N

Description

Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute valid HMACs for arbitrary URLs. Attackers can retrieve HTTP responses from any host reachable by the server, including cloud metadata services and internal network resources.

Basic Information

ID CVE-2026-56285
Source VulnCheck
Published Jun 29, 2026 at 17:13

Affected Product

Vendor zedeus
Product nitter
Affected Versions zedeus nitter 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.