Back to overview

CVE-2026-56285

HIGH Exploitation: PoC
8.6
CVSS 3.1
Description
Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute valid HMACs for arbitrary URLs. Attackers can retrieve HTTP responses from any host reachable by the server, including cloud metadata services and internal network resources.

Metadata

CVE ID
CVE-2026-56285
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-06-20 01:51 UTC
Published
2026-06-29 17:13 UTC
Last updated
2026-06-29 19:26 UTC
Primary CWE
CWE-918
Server-Side Request Forgery (SSRF)
Vendor / Product
zedeus / nitter
Sources
cve.org  ·  NVD

Severity & Metrics

8.6 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
zedeus nitter 0 < 44b2f096f67da2cc257a0e262a94a7ae79e95d47
Weakness (CWE)
CWESourceDescription
CWE-1188 cna Initialization of a Resource with an Insecure Default
CWE-918 cna Server-Side Request Forgery (SSRF)
CVSS scores (2)
ScoreSeverityVersionSourceVector
8.6 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
7.7 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:N/SA:N
Back to overview