PT-2026-94235 · Avideo · Avideo

·

CVE-2026-92912

·

Published

2026-09-17

·

Updated

2026-09-19

CVSS v4.0

8.3

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to c3edcc274c389816d434acadac07ee78eaf330c1
Description The software uses cryptographically weak uniqid() values for RTMP publish keys in LiveTransmition. This reduces key entropy to approximately one million possibilities per second of creation. An attacker with knowledge of the channel creation time can brute-force the five-digit microsecond component to forge valid stream keys and broadcast content as the channel owner.
Recommendations Update AVideo to a version later than c3edcc274c389816d434acadac07ee78eaf330c1.

Exploit

Fix

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92912
GHSA-H983-2MCW-672J

Affected Products

Avideo